evolve or die

ieCache.txt

ieCache.txt
Posted Dec 30, 2004
Authored by Debasis Mohanty | Site hackingspirits.com

When IE is configured to access internet using proxy, the user's authentication details are cached locally without IE prompting the user. Even though the 'save my password' option is not checked, the user's proxy authentication details are cached locally without the user's knowledge.

tags | advisory
MD5 | 5ddedaff2b7e51abc9ab0678dd8c3d05

ieCache.txt

Change Mirror Download
I would like to highlight an issue with IE which I have verified with
Microsoft before posting it here. This issue of IE has got very limited
security implications. I have also included the reply from Microsoft in this
post for reference.

The details of this IE issue can be found below:

Microsoft Internet Explorer User's Authentication Details Sharing
-----------------------------------------------------------------
Details:
When IE is configured to access internet using proxy, the user's
authentication details are cached locally without IE prompting the user.
Even though the "save my password" option is not checked, the user's proxy
authentication details are cached locally without the user's knowledge.

Since, user's details are restricted to each instances of IE and for each
new instances of IE opened by the user will prompt the user for entering
username / password to authenticate to the proxy. But if any html file is
opened locally in IE and then links are used to right-click and open a new
IE window then it doesn't ask for authentication. It is happening because
the saved user's details are being shared by the previously active browser
eventhough the user has not saved the userid/password.

There are two cases when every new instances of IE share the user's
authentication details with the previously active IE instance. They are:

a. If a simple html file (with any hyperlinks in it) is opened locally in IE
then the hyperlinks are used to surf the desired site then IE doesn't prompt
for any user authentication details as it shares the user's credentials from
the previously opened active IE instance.

b. If the user uses right click and open new IE window for any links from an
active IE instance then the new IE window shares the user's credentials from
the previously opened active IE instance.

Note:
# This doesn't happen when a complete new instance of IE is opened to surf
any link.
# This works even the user doesn't check the "save password" option to save
the password details.

I have tested this on the following environment:
Win2K (with SP4) + IE 6.0 and
WinXP (SP1 + hotfixes - SP2) + IE 6.0


Workaround (Provided by Microsoft):
***********************************
What could help resolve this is to perhaps explain the to a user via a Help
link on the credentials dialog that contains more details on just what "save
my password" means.

Patch Details (Provided by Microsoft):
**************************************
We've opened a bug against the product to track this change and this
behavior, and this may be included in a future service pack for the
operating system.



===================================================
Reply From Microsoft
===================================================
From: Microsoft Security Response Center [mailto:secure@microsoft.com]
Sent: Thursday, December 09, 2004 7:05 AM
To: Debasis Mohanty
Cc: Microsoft Security Response Center
Subject: RE: MS IE User's Authentication Details (userid/password) Sharing
vulnerability [5694mr]


Hello Debasis:

We've investigated this and had the teams look at the possible security
related attacks here. From our understanding of the report, the security
implications here seem somewhat limited. Without "save my password"
credentials are persisted within the IE process. With "save my password"
credentials are persisted across IE sessions and IE instances. There may be
some perceived inconsistency, because in the UI, IE instances are not easily
distinguishable from the multiple sessions of a single IE instance.

What could help resolve this is to perhaps explain the to a user via a Help
link on the credentials dialog that contains more details on just what "save
my password" means.

We've opened a bug against the product to track this change and this
behavior, and this may be included in a future service pack for the
operating system.

I appreciate you reporting this to us.

Regards,
--Mike
===================================================

Note: This issue of IE has got very limited security implications.



Thanks & Regards,
Debasis Mohanty
www.hackingspirits.com


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close