Java Applet Can Redirect Browser Traffic New
A security vulnerability exists in the Microsoft Java virtual machine (VM) when used in conjunction with a proxy server could allow a malicious user to redirect and intercept web transmissions.
Issue
The Microsoft VM is a virtual machine for the Win32® operating environment. It runs atop Microsoft Windows® 95, Microsoft Windows 98, ME, Windows NT® 4.0 , Windows 2000® and Windows XP. It ships as part of Windows 98, ME, and Windows 2000 and also as part of Internet Explorer 5.5 and earlier.
The version of the Microsoft VM that ships with Internet Explorer version 4.x and 5.x contains a flaw affecting how Java requests for proxy resources are handled. A malicious Java applet could exploit this flaw to re-direct web traffic once it has left the proxy server to a destination of the attacker’s choice.
An attacker could use this flaw to send a user’s Internet session to a system of his own control, without the user being aware of this. The attacker could then forward the information on to the intended destination, giving the appearance that the session was behaving normally. The attacker could then send his own malicious response, making it seem to come from the intended destination, or could discard the session information, creating the impression of a denial of service. Additionally, the attacker could capture and save the user’s session information. This could enable him to execute a replay attack or to search for sensitive information such as user names or passwords.
A system is only vulnerable if IE is used in conjunction with a proxy server. Users whose browsers are not behind a proxy server are not vulnerable to this vulnerability. However, those users would be vulnerable if they changed their browser to use a proxy server at a later date.
Affected Products
- Microsoft virtual machine (Microsoft VM)
Download
Patch: http://www.microsoft.com/java/vm/dl_vm40.htm
Further Details
Source: Microsoft Corporation
Reference: Microsoft Corporation
Updated: March 4, 2002
>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<
| More Guides » | Registry Guide | Support Forums | Software Guide | Scripting Guide | Search |


