Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » URLs in Internet Explorer 7
Search Topic:
Uniqs:
394
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
AOL techie jailed for selling email database... »
« CNN worm aftermath  
AuthorAll Replies


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire

URLs in Internet Explorer 7

from
»blogs.msdn.com/ie/archive/2005/0···006.aspx
"..
Internet Explorer 7 includes a new URL handling architecture known internally as CURI. The new optimized URI functions provide more secure and consistent parsing of URIs to reduce attack surface and mitigate the threat of malicious URIs.

When designing our security strategy for IE7, malicious URIs were near the top of the list because secure handling of URIs throughout IE is critical to the security of the system. Hence, a major architectural investment was made in CURI for IE7.

Unlike most of the new features in IE7, most end users will never notice CURI working “under the hood” on their behalf. For the technical readers in the audience, however, the details behind CURI may be of some interest. ...

Cudni
--
Think locally, @#!? globally!
Help yourself so God can help you

B
Premium,MVM
join:2000-10-28

Haven't read it, but let me guess -- this is just URLScan and the IIS Lockdown Tool ported to IE, right?

-- B
--
In a realm outside causality and function


keith2468
Premium,MVM
join:2001-02-03
Winnipeg, MB
reply to Cudni
"reduce the attack surface" ???

It sounds like the bulk of someone's security training wasn't in IT security.

inTulsa
Premium
join:2002-02-24

reply to Cudni
quote:
CURI is a lightweight object which holds a single URI in normal form. If the CURI is constructed from a string URI, that string URI is cracked just once when the object is first constructed.
...
The CURI object is available for consumption by external callers like ActiveX controls and Browser Helper Objects; documentation will be provided on MSDN as the CURI class is finalized. It’s worth noting that even external code that does not directly consume CURI objects will benefit from the change, because Unicode string serialized out of CURI objects will be consistently normalized, decreasing the likelihood of incorrect parsing even outside of IE.
It doesn't sound like a security feature at all. They're extending the exposure of the standard old location object with a custom object. The standard URI format hasn't been a source of insecurity - IE's parsing and treatment of it has been. A better approach might be to abide by existing standards - for example, stop accepting intermediate blanks, binary codes, and other garbage in URI. It shouldn't require new object invention to fix the current parsing issues that have led to real vulnerabilities.

I don't want Unicode binary embedded in URI. That will make URL filtering much harder to accomplish. The first to take advantage will probably be advertising and pr0n sites to circumvent today's breed of filters.


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:


1 edit
reply to B
This is taking the many ways of handling URLs, i.e. by clicking links, direct entry into the address bar, etc., and consolidating them into a single piece of code.

This makes it so that there are less places for bugs to hide (hence the "attack surface" comment), and I think it's a great idea. I'm very happy to see this sort of thing from Microsoft; it reinforces the fact that they're serious about security.
--
dmiessler.com - grep understanding knowledge


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

reply to keith2468
said by keith2468 See Profile:

"reduce the attack surface" ???

It sounds like the bulk of someone's security training wasn't in IT security.
There is less code for handling input, and that code is being scrutinized more. That is, most definitely, a security improvement.
--
dmiessler.com - grep understanding knowledge
Forums » Up and Running » Security » SecurityAOL techie jailed for selling email database... »
« CNN worm aftermath  


Friday, 04-Dec 12:46:57 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [144] Avast Antivirus Has Gone Mad
· [116] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [96] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [72] Sprint Defuses GPS Privacy Media Bomb
· [71] FCC Ponders Moving From PSTN To IP Voice
· [70] Baltimore To Ban Lazy Cable Installs
· [64] Broadband Killed The Game Console
Most people now reading
· False positive in Avast! or is it real? [Security]
· Linux is terrorist - according to MS... [All Things Unix]
· [WotLK] Doing away w/ conquest? [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· An Excellent Guide About Google Voice And Sip Sorcery [VOIP Tech Chat]
· Google takes aim at browser redirection [Security]
· [Scam] Cruise line mail? [Spam, Scam and Phishbusters]
· Windows 7 boot manager editing questions [Microsoft Help]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]