Open source IE patch hits trust barrier

Openwares.org, an open-source software development Web site, has posted a patch that purports to fix a critical vulnerability in Microsoft's Internet Explorer browser, but software developers and analysts are advising against installing it.

The vulnerability in question allows IE to display one URL in the address bar while the page being viewed is actually hosted elsewhere. This makes users more susceptible to ruses such as phishing, in which online-banking users receive emails that seem to have been sent by their bank, asking them to click on a link in order to visit the bank's Web site and "confirm" their security access details. Crude phishing attempts are obvious because the address bar in Internet Explorer would show a URL different to that of the bank, but elaborate phishing schemes could exploit the IE vulnerability and therefore make the ploy more plausible.

Despite the apparent attraction of downloading the patch - for which Microsoft as yet has no equivalent -- analysts warned against doing so. Graham Titterington, principal analyst at Ovum, is suspicious of the update and advises companies to wait till Microsoft releases an official patch, because although the Openwares.org patch may work, it could cause problems with future Microsoft updates. "They don't have access to the source code and Microsoft does," said Titterington. "Even if it is a bona fide patch and it works, how compatible will it be with future Microsoft patches that come along?"

According to Opensource.org, the patch has been downloaded around 1,000 times since it was published on Monday. The site publishes software that has been written and submitted by its readers, raising concerns on developer discussion groups about the motivations of the writer. Some developers are wary of the patch because its code sends URLs back to the author's servers, which could be a privacy threat in itself. Advocates say such action may well be necessary to help the code do its job, particularly since only suspect URLs were redirected. And some contributors welcomed the patch because although it has been almost two weeks since Microsoft admitted the vulnerability exists, it has not yet released its own fix.

But Titterington advises companies to wait for the official patch from Microsoft: "Microsoft is going to have to patch it -- this came into the public domain with MS unprepared so there will be a time lag involved, so organisations are advised to sit tight and wait for Microsoft patch to come along," he said.

Microsoft was unable to comment on its progress towards creating a patch or give any advice on whether the open-source patch should be used or not; but in the company's Knowledge Base support Web site, among other solutions, users are advised to view links in notepad before clicking on them to identify the actual destination. One basic rule of thumb says that if the URL contains "%00", "%01" or "@" characters, it is suspicious, if it does not, it is probably safe to click. Alternative browsers, such as Mozilla and Opera, are not affected by the problem.

Advertisement

Talkback 0 comments


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Jude Willis Why eBay tried to screw Aussie users
    Now that the bizarre ruckus over eBay's proposed PayPal monopoly appears totalled, it seems a good time to ponder why eBay chose Australia to risk its reputation on such a massively unpopular scheme.
  • Array The more things change…
    With all the excitement over the iPhone, few people have noticed that 1 July was the 11th anniversary of the deregulation of Australia's telecommunications market.
  • Array I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • More blogs »

Tags

Back to top

Featured