Gartner: Beware of Bofra exploit

Hackers are set to increase their use of banner ad exploits as a means of gaining remote control of computers.

Analyst firm Gartner has predicted that attacks using the Bofra (buffer overflow frame exploit) or IFRAME exploit will become more common, especially around systems with sloppy patching.

In an emailed report issued on Thursday, the company said: "Gartner believes that attacks of this type will become increasingly common, especially around transition points -- systems where multiple versions of software (such as Windows 2000 and XP) are in use without full patches across both platforms."

The Bofra attack exploits an unpatched Internet Explorer 6.0 browser vulnerability, affecting Windows 2000 and Windows XP Service Pack 1 (SP1). Computers running SP2 not affected by the bug, but Apache Web servers are. The analyst company recommended businesses using Apache Web servers to apply security patches as soon as possible.

Earlier this year, Gartner publicly attacked Microsoft, saying companies should not expect the software giant to protect them.

"We've all been part of the biggest beta test the world has ever known -- Windows. Microsoft will not solve all of the security problems, no matter what the richest man in the world says," said Gartner vice-president Victor Wheatman in a keynote speech at Gartner's IT Security Summit in London.

Wheatman added that removing faulty software during operation was costing firms up to 5 percent more than finding flaws during testing.

Like this article? Click below to send it to your mobile for free!

Talkback 1 comments

  1. How on earth are Apache web servers vulnerable to a Microsoft IE exploit? What the...? Anonymous -- 29/11/04

    How on earth are Apache web servers vulnerable to a Microsoft IE exploit? What the...?


Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured