Friday, June 07, 2002


…Gopher, was once used to organize and show pages on the Internet before today's HTML technology. IE contains support for Gopher, and it's the part of the code that parses Gopher replies that has an "exploitable buffer overflow bug." If a buffer overflow is triggered, new code overwrites the buffer. This affects several versions of IE, including 5.5 and 6.0.

That means that it's possible for a hacker to attack via an HTML e-mail message or a web page that that leads back to the hacker's Gopher server. The server can trigger a buffer overflow, overwrite the buffer with the hacker's new, malicious code, and gain access to the victim's computer, including retrieving, installing, or removing files.
http://www.pcmag.com/article/0,2997,s=1490&a=27821,00.asp

No comments:

Post a Comment

con·cept