Security hole in IE tracks user's mouse movements
|
by tech2 News Staff
|
|
A security hole discovered in Internet Explorer has been found to be potent enough to track a user's cursor movements, even if their window is inactive, minimised or unfocused. Naked Security reports that the vulnerability was first brought to light by spider.io, vendor of a hosted platform that the company says allows users to distinguish between human website visitors and bots in real time. Interestingly, Spider.io informed the existence of the flaw to Microsoft in October, while adding that the IE version 6-10 were affected. While Microsoft Security Research Center admitted to there being a flaw, it informed spider.io that it has "no immediate plans" to patch it in existing browser versions; it was then that it revealed the flaw.
The security loophole essentially allows attackers to track an IE user's mouse movements, even if they haven't installed any software as such. All that attackers have to do is buy a display ad slot on any website. Spider.io adds, "This is not restricted to lowbrow porn and file-sharing sites. Through today’s ad exchanges, any site from YouTube to the New York Times is a possible attack vector."
The video below demonstrates the loophole
Dean Hachamovitch, Corporate Vice President, Internet Explorer, has on his part elaborated, "We are actively working to adjust this behavior in IE. There are similar capabilities available in other browsers. Analytics firms can expect to do viewpoint detection in IE similarly to how they do this in other browsers. We will update this blog with more information as it is available."
"The loophole is actively being exploited by at least two display ad analytics companies across billions of webpage impressions each month," spider.io says. The report highlights that this holds true for any page that is open, even if a visitor pushes it to a background tab or minimises IE altogether, since a mouse cursor can be tracked across the user's entire display.
The vulnerability allows attackers to steal passwords and credit card information without having to even install a keylogger. "Of course, as spider.io says, virtual keyboards are typically used to reduce the chance that a hacker can record keypresses with hardware keyboard interceptors or keyloggers," the report adds.
Hachamovitch adds, “From investigating the specific behavior when mouse position data is visible outside the browser window, sites can view only the mouse state; they cannot view the actual content that the user is interacting with. From our conversations with security researchers across the industry, we see very little risk to consumers at this time. As we have stated previously, there are no reported cases of any consumer having their information compromised.”
Cover image credit: Getty Images |
Tags: Internet Explorer , cursor movements , IE , Microsoft , Microsoft IE , IE version 6-10 , mouse cursor movements
SPOTLIGHT
10.1-inch Sony Xperia Tablet Z launches at...
20 May, 2013, 05:16 PM
5 Online test prep sites for GRE
20 May, 2013, 06:17 PM
How To: Root the Samsung Galaxy S4 I9500
20 May, 2013, 02:25 PM
Is Samsung 'mentally enslaving' Indian smartphone buyers...
17 May, 2013, 07:51 PM IST
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
17 May, 2013, 01:09 PM IST
tech2 live: The latest from Google I/O 2013
16 May, 2013, 01:56 PM IST
MouthShut.com petitions SC to protect freedom of expression and quash
09 May, 2013, 07:01 PM IST
5 Online test prep sites for GRE
20 May, 2013, 06:17 PM IST
Hollywood studios ask Google to take down links to The Pirate Bay documentary
20 May, 2013, 08:08 PM
Samsung grabs 95 percent share of global Android smartphone profits
20 May, 2013, 05:08 PM
Stuxnet virus strengthened Iranian nuclear programme: Report
20 May, 2013, 05:01 PM
5 Online test prep sites for GRE
While GRE coaching classes are limited and not necessarily in every city,...
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
To avoid all the hassle and with a view to make it convenient for...
We have 5 tech gift ideas that will help you find a gift that will...
T-Shirt Loot
Mon May 20, 19:09:55
5 Online test prep sites for GRE
Ankit Shetty
Mon May 20, 19:01:30
4.7-inch Galaxy Grand Quattro launched for Rs 17,290
Rahul Nargundkar
Mon May 20, 18:48:14
Jolla's new Sailfish smartphone price
4.7-inch Galaxy Grand Quattro launched for
10.1-inch Sony Xperia Tablet Z launches at
Samsung Galaxy Tab 3 10.1 specs seen in...
The new Xbox will be unveiled tomorrow;...
Digital version of The Last of Us will be...

















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace



















