Technology Review - Published By MIT
Advertisement

TR Editors' blog

Insights, opinions, and our editors' analysis of the latest in emerging technologies.

Blog Topics

Recent Posts

Recent Comments

  • masal : korgrolandyamahamd altyapidemoketron
  • ... : Just sayin'. Related: News outlets use the same technique to create value-free "content" to match...
  • Phineas : your advice is that I put up a blog claiming the outcome of Charles B Rangel's ethics hearing and...
  • mattgroom : While we may not be able to transport the extra energy in our current wiring...why bother...  Use...
  • wctopp : You can now legally "jailbreak" an iPhone and use it on another network.  You cannot, however,...
Advertisement
Thursday, January 14, 2010

Internet Explorer Flaw Implicated in Chinese Attacks

A bug in the browser was a key part of recent attacks by Chinese hackers.
By Erica Naone

George Kurtz, CTO of McAfee Security, revealed new details of the recent attack on Google and other companies in a blog post this afternoon. A "zero-day" bug--a previously undiscovered vulnerability--in Microsoft's Internet Explorer browser seems to have been a key part of the attack.

The attack on Google's infrastructure, which Kurtz calls "Operation Aurora," was able to steal some of the Web giant's intellectual property, apparently in the process of pursuing access to the e-mail accounts of Chinese human-rights activists. Google has said that the same attack hit at least 20 other large companies.

Yesterday, I reported that the attackers likely used social engineering techniques to get into Google's infrastructure, and Kurtz's post confirms this--attackers tricked company employees into clicking malicious links in an e-mail. But once those links were clicked, they activated malware that exploited Internet Explorer.

Kurtz writes:

Our investigation has shown that Internet Explorer is vulnerable on all of Microsoft's most recent operating system releases, including Windows 7. ... While we have identified the Internet Explorer vulnerability as one of the vectors of attack in this incident, many of these targeted attacks often involve a cocktail of zero-day vulnerabilities combined with sophisticated social engineering scenarios. So there very well may be other attack vectors that are not known to us at this time. That said, contrary to some reports our findings to date have not shown a vulnerability in Adobe Reader being a factor in these attacks.

Kurtz doesn't specify which of the affected companies were infiltrated through the bug in Internet Explorer, but I'm hoping Google wasn't one of them. Wouldn't Google's employees have been using its own Chrome browser?

Microsoft is expected to release more information at this location.

Comments

Advertisement

Log In

Forgot your password?     Register »
Advertisement
Technology Review July/August 2010

Current Issue

Can AIDS Be Cured?
Researchers are pursuing radical new strategies to eliminate HIV from the body.
•  Subscribe
Save 36%
•  Table of Contents
•  MIT News
» Gift Subscription
» Digital Subscription
» Reprints, Back Issues
» Subscribe
» Table of Contents
» MIT News

More Technology News from Forbes

Advertisement
MIT Massachusetts Institute of Technology © 2010 Technology Review. All Rights Reserved.