Australian researcher uncovers XP vulnerability

Unwary Windows XP users can have entire directories emptied of files simply by clicking on a hyperlink, according to an Australian security researcher.

The vulnerability occurs when a particular request (in the form of a command in the URL address box) is sent to the Win-XP Help Centre, which then runs a script to delete a file which is derived from the URL. The vulnerability has been posted on security sites.

Shane Hird, a research scientist at the Distributed Systems Technology Centre at the University of Queensland told ZDNet Australia he discovered the vulnerability near the end of June. "I was playing around and it looked a bit suspicious," he said. "I noticed it required a file name and then that file was deleted."

Although the vulnerability cannot be forced on a user because it requires someone to actively click on a hyperlink, it is considered dangerous because the casual user may mistake it for a normal link.

"It's high risk because it's so easy," said Hird. "Everyone just clicks on links, they don't really check where they go."

Hird contacted Microsoft, and they worked together to determine the scope of the vulnerability. Microsoft has fixed the vulnerability through its Windows XP Service Pack One (SP1). Microsoft revealed that when they checked neighbouring features and functions for similar vulnerabilities they found some, which are also fixed through the patch.

"When I went back and looked [at the code] a lot of files had been changed," said Hird. "There probably are a lot more serious problems there that I haven't had time to look at."

Advertisement

Talkback 3 comments

    he didn't discover jack. give credit to the underground where the exploit came from, not some univerity ****!Anonymous -- 17/09/02

    he didn't discover jack.

    give credit to the underground where the exploit came from, not some univerity ****!

    hear hear !~!!~Underground supporter -- 18/09/02

    hear hear !~!!~

    I heard if you click on www.redhat.com, www.suse.com, or www.mandrakelinux.com it makes all of Windows XP go away...Anonymous -- 20/09/02

    I heard if you click on www.redhat.com, www.suse.com, or www.mandrakelinux.com it makes all of Windows XP go away...

Add your opinion


Latest Videos

Blogs

  • Renai LeMay Datacentre disaster lessons
    As a system administrator, the health and status of your datacentre is at the forefront of your mind. But how often do you think about the needs beyond server status and bandwidth?
  • Array E-health too unsexy for COAG
    There will always be something more politically sexy than e-health for state governments, meaning the National E-Health Transition Authority's business case for a national electronic medical record might just sit on the shelf gathering dust forever.
  • Array TelstraUnClear
    Telstra's New Zealand arm TelstraClear is one strange company ...
  • More blogs »

Tags

Back to top

Featured