R E L A T E D   C O N T E N T
ADVERTISEMENT

Netscape users exposed to 'serious' bug

A serious and as yet unfixed bug in Netscape's Java distribution means that home computers are open to attack simply if users are unlucky enough to visit a website containing malicious code.

John Leyden, vnunet.com 09 Aug 2000
ADVERTISEMENT

A serious and as yet unfixed bug in Netscape's Java distribution means that home computers are open to attack simply if users are unlucky enough to visit a website containing malicious code.

The problem has emerged following the posting on the internet of code, dubbed Brown Orifice by its developer Dan Brumleve, which exploits a vulnerability in AOL's Netscape Navigator browser to allow an attacker to view the contents of a user's hard drive.

As yet, Netscape has not made a patch available to address the vulnerability and security experts advise that the only effective interim defence against the problem is to turn off Java in Navigator.

All versions of Netscape Navigator and Netscape Communicator versions 4.74 and earlier are vulnerable when Java is enabled. The flaw is not platform specific and systems running Windows 2000, Windows NT and Linux are known to be vulnerable through demonstration, although it is believed that Apple Macintosh users might be immune.

Matt Tomlinson, business development director at MIS Corporate Defence, said the malicious Java code uses a hole in Netscape to allow an attacker to access a user's environment.

He said users on local area networks should be protected by their firewalls, which commonly scan for malicious code, but the implications for home users are potentially "extremely serious" because the code can be modified to perform other functions.

"We believe that this exploit goes beyond file sharing and would allow an attacker to read email or perform port scanning. Anything you do from your desktop might be possible using this malicious Java code," said Tomlinson.

Richard Stagg, senior security architect at Information Risk Management, said the problem is one of the few that affect Netscape Navigator and not Internet Explorer, and added that it is more serious for home users.

He explained this is because in a corporate environment most internet connections go through a proxy server, which would guard against the exploit - but domestic users have no such defence.

"Home users are in genuine danger of having their files ripped. The only security recommendation on this is to turn off Java - but then things stop working," said Stagg.

Netscape declined to comment on the problem.

To turn Java off in Netscape Navigator:

1) Select Edit, then Preferences

2) Click on Advanced, then un-check the box next to 'Enable Java'

See also:

The Cult of the Dead Cow, a group best known for its creation of the Back Orifice tool which has gained notoriety over the last few years, is working on an anti-censorship web browsing system.  29 Apr 2001
Netscape has today finally launched the latest version of its browser software in an attempt to regain lost share against Microsoft's Internet Explorer.  14 Nov 2000
Netscape has redesigned its website to better integrate applications and content with its upcoming browser release.  04 Oct 2000
Microsoft has issued a patch for a security hole in Office 2000, which while not critical, places a heavy burden on major users.  11 Aug 2000
bugwatchThe end of last week saw further exploitation of UK company websites by what is a recurring threat in the IT world - the hacker. Five companies were hacked last week, but not by bored 'script kiddies', or those who do it just for fun. Three of the hacks were executed by GForce, a group which aims to raise awareness of the Indian government's treatment of Kashmir nationals.  11 Aug 2000
Microsoft has issued a patch for a vulnerability in its Outlook messaging software that could allow an attacker to use a message formatted in HTML to read files on a victim's machine.  27 Jul 2000
A security hole that could expose private files has been discovered in Netscape Communicator.  21 Apr 2000
Microsoft has acknowledged that its engineers substituted certain file names with the phrase, "Netscape engineers are weenies," in some of its internet software.  17 Apr 2000

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
Our noteworthy client in the South West requires a C#.NET Developer to help develop and rewrite their Finance Systems interfaces. The ideal candidate will be available immediately and be a strong developer using C#.NET. You ... more >
| JAM Recruitment
Job Reference: 21307 Job Title: Project Manager (HR amp; Payroll technology transformation? Do you have Project Management experience gained within client facing projects? Are you a forward thinking professional, comfortable with people management? The Background ... more >
| JAM Recruitment
Position: HRIS Specialist Reference: 21191 Salary: c£40-50k + Excellent Benefits Location: West Midlands Contact: Chris Pearson - JAM HR Systems Are you a techno-functional professional with a background in developing and driving HR Information Systems? ... more >
| JAM Recruitment
Position: EMEA HR Systems Manager Reference: 21014 Salary: c£55-65,000 + Bonus + Benefits Location: North London Contact: Chris Pearson - JAM HR Systems Are you a proven HR technology leader with aptitude to drive international ... more >
More job opportunities