Microsoft to patch bug used in Google hack
- 15 January, 2010 11:49
- Comments
Microsoft is scrambling to patch an Internet Explorer flaw that was used to hack into Google's corporate networks last month.
The attack was used to hack into networks at 34 companies, including Adobe, security experts say. Typically such hacks involve several such attacks, but the IE bug is the only one definitively linked to the hacking incident, which security experts say originated in China.
In a security advisory released Thursday, Microsoft said IE 6 users on Windows XP are most at risk from the flaw, but that other users could be affected by modified versions of the attack.
Microsoft said it is developing a fix, but it did not say when it expects to patch the issue. The company is slated to release its next set of security updates on Feb. 9.
A Google spokesman confirmed Thursday that the Internet Explorer attack was used against Google and that the company then reported the issue to Microsoft.
Google learned of the issue in December and, after discovering the server used to control the hacked computers, notified other companies affected by the hack. Apparently convinced that the infiltration was sanctioned by the Chinese government, Google has threatened to effectively pull its business out of China.
McAfee released a description of the attack Thursday, saying that the people hit with the attack were probably "targeted because they likely had access to valuable intellectual property."
Microsoft condemned the attack Thursday, but said it had no indication that its corporate network or mail products were hit.
Although the IE attack has only been seen in "targeted and limited" incidents, Microsoft may release an emergency patch for the product, the company said.
The malicious code that hit Google "attacks IE6 on XP exclusively," but is thwarted by the Data Execution Prevention (DEP) technology used by Windows XP, said Dan Kaminsky, director of penetration testing with IOActive. However, he added, the bug could be leveraged in attacks that affected more recent versions of IE, running on Windows XP, he added. Vista and Windows 7 use a more advanced protection technology called ASLR (address space layout randomization) that makes exploiting this bug extremely difficult.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Microsoft Security Advisory (979352): Vulnerability in Internet Explorer Could Allow Remote Code Execution
- McAfee Security Insights Blog » Blog Archive » Operation “Aurora” Hit Google, Others
- The Microsoft Blog – News and Perspectives from Microsoft : The Recent Cyber Attacks
- The Microsoft Security Response Center (MSRC) : Security Advisory 979352 Released
- Is your data center ready for virtualisation? Important power considerations for virtualised IT environments
- Customer Case Study: Yarra Valley Water Turns to Enterprise Software to Improve Information Flow
- Improving the Management and Sharing of Massive Data Volumes
- Why Encrypt? Securing Email without compromising communications.
- CommVault Extends its Data Protection and Information Management Strategy with Simpana 9
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Nokia N9: Why you shouldn't buy this device
-
Microsoft at a loss over Event Viewer scam
-
Office 2007 for Dummies
-
Windows 7 for Seniors for Dummies®
-
Teach Yourself Visually Windows 7
-
Computers for Seniors for Dummies, 2nd Edition
-
Windows 7 for Dummies® Dvd+book Bundle
-
MYOB Software for Dummies 6E Australian Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Microsoft Office
-
Office 2007 All-In-One Desk Reference for Dummies












Comments
Post new comment