Great Circle Associates Firewalls
(August 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: MS Explorer 3.0 'Serious security flaw'?
From: Bill Stout <bill . stout @ hidata . com>
Date: Fri, 23 Aug 1996 16:34:29 -0700
To: Ashwin Kumar <kumar @ ibu . sj . nec . com>, Bill Stout <bill . stout @ osc . hidata . com>
Cc: Firewalls @ GreatCircle . COM

At 02:13 PM 8/23/96 -0700, Ashwin Kumar wrote:
>On Fri, 23 Aug 1996, Bill Stout wrote:
>:Anyone know what the 'serious security flaw' is in MS Explorer 3.0?

<snip>

>The core of the attack is a technique for delivering a document to the
>victim's browser while bypassing the security checks that would normally
>be applied to the document. If the document is, for example, a Microsoft
>Word template, it could contain a macro that executes any DOS
>command. The attacker could arrange things so the macro was executed
>automatically as a consequence of the victim visiting the attacker's
>page.

<snip>

What makes this an Explorer-specific problem?

If I'm not mistaken, _any_ browser will open a .doc or .xls document if the
helper application is defined.  Word and Excel macro viruses are not news.
I thought it would've been an Active-X or e-mail scamming hole.

I don't think a firewall can be configured to filter Word/Excel macro viruses.


Bill Stout
_______________________________________________________________________________
Senior Systems Admin   NT/UNIX/I-net/Routers/Mainframes/Janitor ;)
Hitachi Data Systems   408-970-4822   ---  Disclaimer:  I speak only for myself
___________"Infowar, Cyber-war, yes, 'they' _are_ out to get you..."___________



Follow-Ups:
Indexed By Date Previous: Re: [NOISE] Industry analyst nonsense (was: RE: CheckPoint FireWall-1 v2.1)
From: Lord Soth <soth @ soth . users . mindspring . com>
Next: Re: Unix-based viri scanner
From: Robert Hanson <roberth @ cet . com>
Indexed By Thread Previous: Re: MS Explorer 3.0 'Serious security flaw'?
From: Jim Wamsley 303-673-8163 <jim @ coltano . stortek . com>
Next: Re: MS Explorer 3.0 'Serious security flaw'?
From: Ashwin Kumar <kumar @ ibu . sj . nec . com>

Google
 
Search Internet Search www.greatcircle.com