Microsoft Warns of XP Help Function Security Flaw
Microsoft has identified a potential security risk in the Help function of Windows XP. But there is some controversy over the way the issue has come to light.
This bug involves XP's Help and Support Center, and specifically a style of link which routes a browser to a help page built into Windows rather than a web page. Such links begin hcp:// rather than the more familiar http:// and are a way of making it easier to give online help and advice by allowing writers to include smooth links to Windows' own help pages.
Whitelist Help Pages Spoofed
Tavis Ormandy, an information security engineer for Google, says he's found a security hole. In theory any click on an hcp:// link checks the target page against a "whitelist" of genuine help pages to make sure links can't be used to route users to malicious content.
Ormandy says that by following a particular process, which is admittedly somewhat complex, a would-be hacker could get round this whitelist check and trick the users into running the malicious content. It appears that the issue could be exploited in any web browser, but is a higher risk if using Internet Explorer.
Microsoft Gets Five Day Headstart
Google's Ormandy has now published details of the problem, and how it could be exploited, on a security website known as Full Disclosure. That's not gone down well with everyone, as the posting came just five days after Ormandy informed Microsoft about the issue.
Microsoft requests that people in the security industry operate a policy dubbed "responsible disclosure" by which they do not publicize details of security flaws until Microsoft has a full fix in place. Of course, there's no way for Microsoft to enforce that request, and some researchers argue that it's in the public interest to get details out as soon as possible.
Ormandy argues that he needed to discuss the bug with other security researchers so that he could find a way to prove that it really could be exploited; without such proof, he believes his report would not have been compelling enough for Microsoft to take any notice (partly because it deals with so many potential bugs).
However, according to Ormandy, such discussion would have been impossible if he stuck to Microsoft's disclosure policies. (Source: seclists.org)
Microsoft is investigating fixes to the bug. In the meantime it has published details of how users can disable the hcp:// link feature if they are concerned about potential abuses. (Source: microsoft.com)
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.