Hackers find a hole in Internet Explorer browser

  • By Will Oremus Slate
  • Tuesday, September 18, 2012 3:45pm
  • Business

In an alarming development for both Microsoft and the millions who use its Internet Explorer browsers, hackers have found a security hole that allows them to install malicious software on Windows XP computers. Specifically, security researcher Eric Romang of Zataz.com discovered on Sunday that the fresh “zero day” vulnerability allowed cybercrooks to use a form of the old Poison Ivy trojan horse to take control of victims’ machines. The flaw appears to affect Internet Explorer versions 6, 7, 8, and 9, though not the brand-new version 10 (which is only available on Windows 8). It seems the culprits may be related to the bunch who exploited a major flaw in Oracle’s Java browser plug-in last month.

When news of the Java vulnerability broke, security experts’ advice was clear-cut: Disable the Java browser plug-in immediately unless you absolutely need it. The fact that Java applets have grown relatively scarce on the Web, coupled with Oracle’s sluggish response to the problem, made that an easy call for most. (Java has since patched the hole, for what it’s worth.)

So if you’re a Windows XP user, should you now dump Internet Explorer as well? Perhaps, experts say, though the hack shouldn’t be a cause for mass panic. For one thing, Microsoft itself has responded quickly with a security advisory that includes an extensive list of work-arounds. Its apparent sense of urgency suggests that it may offer a prompt update that patches the problem, though it hasn’t done so yet.

Unfortunately for Microsoft, the work-arounds are a bit cumbersome and could affect your browsing experience – potentially more so than just switching to another browser. And while IE loyalists could just try to avoid potentially malicious websites and hope for the best, you never know. “I would recommend not using Internet Explorer until this issue is patched,” Sophos’ Chet Wisniewksi says. “While the exploit is not in widespread use, it could be integrated into popular attack kits like the Blackhole Exploit Kit any time now.”

For those who were already thinking of switching to another browser, such as Google’s super-fast Chrome, Mozilla’s highly customizable Firefox, or Opera, consider this the perfect time. If you don’t like it, you can come back to IE once Microsoft fixes this flaw.

bc-hackers

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

The livery on a Boeing plane. (Christopher Pike / Bloomberg)
Former Lockheed Martin CFO joins Boeing as top financial officer

Boeing’s Chief Financial Officer is being replaced by a former CFO at… Continue reading

Izaac Escalante-Alvarez unpacks a new milling machine at the new Boeing machinists union’s apprentice training center on Friday, June 6, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Boeing Machinists union training center opens in Everett

The new center aims to give workers an inside track at Boeing jobs.

Some SnoCo stores see shortages after cyberattack on grocery supplier

Some stores, such as Whole Foods and US Foods CHEF’STORE, informed customers that some items may be temporarily unavailable.

People take photos and videos as the first Frontier Arlines flight arrives at Paine Field Airport under a water cannon salute on Monday, June 2, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Water cannons salute Frontier on its first day at Paine Field

Frontier Airlines joins Alaska Airlines in offering service Snohomish County passengers.

Amit B. Singh, president of Edmonds Community College. 201008
Edmonds College and schools continue diversity programs

Educational diversity programs are alive and well in Snohomish County.

A standard jet fuel, left, burns with extensive smoke output while a 50 percent SAF drop-in jet fuel, right, puts off less smoke during a demonstration of the difference in fuel emissions on Tuesday, March 28, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Sustainable aviation fuel center gets funding boost

A planned research and development center focused on sustainable aviation… Continue reading

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Helion celebrates smoother path to fusion energy site approval

Helion CEO applauds legislation signed by Gov. Bob Ferguson expected to streamline site selection process.

Water drips from an Alaska Airlines Boeing 737 after it received a water salute while becoming the first scheduled 737 arrival Thursday, Feb. 17, 2022, at Paine Field Airport in Everett, Washington. (Ryan Berry / The Herald)
Boeing and Airbus forecast strong demand for their jets

Boeing and Airbus project more than 40,000 new jets are needed.

Hundreds wait in line to order after the grand opening of Dick’s Drive-In’s new location in Everett on Thursday, June 12, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Dick’s Drive-In throws a party for opening day in Everett

More than 150 people showed up to celebrate the grand opening for the newest Dick’s in Snohomish County.

Patrick Russell, left, Jill Russell and their son Jackson Russell of Lake Stevens enjoy Dick’s burgers on their way home from Seattle on Friday, Sept. 22, 2023 in Edmonds, Washington. The family said the announcement of the Dick’s location in Everett “is amazing” and they will be stopping by whenever it opens in 2025. (Olivia Vanni / The Herald)
Dick’s Drive-In announces details for Thursday’s grand opening in Everett

Dick’s will celebrate its second Snohomish County location with four days of festivities.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.