Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Windows Secrets>Internet Explorer flaw exposes FTP credentials

Internet Explorer flaw exposes FTP credentials

Tweet

Chris mosby By Chris Mosby

Among the patches Microsoft released on Patch Tuesday this week is yet another cumulative rollup for the company’s Internet Explorer browser.

But an IE flaw that’s been present at least since 2004 is still unpatched, because Microsoft never released a patch for IE 6 and allowed the flaw to remain in IE 7.


IE feature reveals usernames and passwords

Brian Krebs, who writes a computer security blog for the Washington Post, recently reported a flaw in IE that he learned about while attending the recent DEFCON hacker conference in Las Vegas.

Krebs says he learned that IE 6 and 7 cause your FTP (File Transfer Protocol) username and password to be saved into any .htm, .html, or .mht file that you download to your local computer.

If you modify and then upload that file from your computer back to the FTP server, all someone has to do is view the source of that file and your FTP credentials are in plain sight. With that information, a hacker could do just about anything to your Web site that he or she wanted.

According to Krebs, his source says Microsoft was informed about this problem in IE 6, way before IE 7 was released. Microsoft allegedly told Krebs’ source that it would take a rebuilding of the entire feature to fix the problem.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Microsoft warns of unpatched flaw in Internet Explorer
  2. Flaw in Java affects Internet Explorer and Firefox
  3. Internet Explorer has triple security threat
  4. More security woes for Internet Explorer
  5. Flaw in latest Oracle software exposes e-commerce data
= Paid content

All Windows Secrets articles posted on 2007-08-16:

  • Introduction Next issue Sept. 6 — take a break!
  • Top Story Media players more dangerous than Windows
  • Known Issues Restrict application privileges for greater security
  • Wacky Web Week Is there a movie idea on your Start Menu?
  • Woody's Windows Here’s the real Start Menu entry
  • PC Tune-Up How to get private, anonymous Web surfing
  • Windows Secrets Internet Explorer flaw exposes FTP credentials
  • Patch Watch Malware cocktails sure to hit unpatched PCs
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb