Microsoft to patch bug used in Google hack
IDG News Service - Microsoft is scrambling to patch an Internet Explorer flaw that was used to hack into Google's corporate networks last month.
The attack was used to hack into networks at 34 companies, including Adobe, security experts say. Typically such hacks involve several such attacks, but the IE bug is the only one definitively linked to the hacking incident, which security experts say originated in China.
In a security advisory released Thursday, Microsoft said IE 6 users on Windows XP are most at risk from the flaw, but that other users could be affected by modified versions of the attack.
Microsoft said it is developing a fix, but it did not say when it expects to patch the issue. The company is slated to release its next set of security updates on Feb. 9.
A Google spokesman confirmed Thursday that the Internet Explorer attack was used against Google and that the company then reported the issue to Microsoft.
Google learned of the issue in December and, after discovering the server used to control the hacked computers, notified other companies affected by the hack. Apparently convinced that the infiltration was sanctioned by the Chinese government, Google has threatened to effectively pull its business out of China.
McAfee released a description of the attack Thursday, saying that the people hit with the attack were probably "targeted because they likely had access to valuable intellectual property."
Microsoft condemned the attack Thursday, but said it had no indication that its corporate network or mail products were hit.
Although the IE attack has only been seen in "targeted and limited" incidents, Microsoft may release an emergency patch for the product, the company said.
The malicious code that hit Google "attacks IE6 on XP exclusively," but is thwarted by the Data Execution Prevention (DEP) technology used by Windows XP, said Dan Kaminsky, director of penetration testing with IOActive. However, he added, the bug could be leveraged in attacks that affected more recent versions of IE, running on Windows XP, he added. Vista and Windows 7 use a more advanced protection technology called ASLR (address space layout randomization) that makes exploiting this bug extremely difficult.
Web giants attacked
- White House orders security review in wake of WikiLeaks disclosure
- Leaked U.S. document links China to Google attack
- Update: Researchers track cyber-espionage ring to China
- Google, China now playing cat and mouse?
- McAfee: 'Amateur' malware not used in Google attacks
- Military warns of 'increasingly active' cyber-threat from China
- China: Google 'totally wrong' to stop censoring
- Update: Google stops censoring in China
- Google's China ad partners wait in 'incomparable pain'
- Google may soon leave China, reports say


Last month I blogged about the partnerships you should build inside your organization. In keeping with that tone it's time we discussed expanding that partnership mentality to include some of the best technical resources you can ever get hold of, those are the ones that work in your neighboring cities, municipalities, counties, regions, townships etc. Come on folks, these people are already doing exactly the same things as you!
- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Plugging Information Leaks
- Unlike traditional data leak prevention solutions, which work at the network or desktop level, Attachmate Luminet software monitors end-user activity at the application...
- Shine a Light on Insider Abuse
- This solution brief describes the four technical challenges you face and tells you how Luminet can help you overcome them.
- Threats from Within Your Government Agency
- This solution brief tells how Attachmate Luminet fraud management software can help government agencies and departments get ahead of the fraud curve-by providing...
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how...
All Government IT White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Government IT Webcasts

