index home News audio search help techcity computerworld
News analysis

Bell Labs uncovers JavaScript bug

This week's browser bug is brought to you courtesy of Bell Labs, where a researcher discovered what is being described as a "significant flaw" in the JavaScript language used in World Wide Web browsers from Microsoft Corp. and Netscape Communications Corp.

Both Netscape and Microsoft are working on fixes for the problem. Netscape already has a bug fix on its Web site for Navigator 3.x and will post a fix for Communicator 4.0 next week, according to David Andrews, senior security product manager.

"Let's get this straight. This flaw does not allow hackers to gain access to what is held on a user's hard disk," Andrews said. "It allows information being passed between a user and an unscrupulous Web site, such as cookies and [uniform resource locators], to be captured."

The flaw, discovered by researcher Vinod Anupam, also enables an unscrupulous Web site to load a Trojan horse and gain access to information a user is filling out on a form on the site, Bell Labs officials explained.

"The easiest way to disable the flaw is to turn off JavaScript," said Chris Pfaff, spokesman for Bell Labs. "We actually discovered the flaw on June 24, and we notified both Netscape and Microsoft."

Although no incidents of attacks have been reported, this problem highlights credibility concerns about the industry, according to users. "The seriousness of the flaw is almost irrelevant," said Wilton Risenhover, CEO of X-Radio, Inc., a Web-based alternative music store in San Francisco. "I would almost prefer some stability to all this bleeding-edge technology in Java, because every time there is a bug scare, the world just shakes its head and asks when the engineers are going to be able to make the Web safe for us to spend money."

However, one analyst wasn't that concerned. "It's good that these bugs are being discovered. What you have to understand is that this is a very immature industry," said Evan Quinn, an analyst at International Data Corp. in Mountain View, Calif. "But I don't think that this is going to bring either Netscape or Microsoft to its knees."

Last updated on 07/11/97



Search
Enter
words describing a concept or
keywords you wish to find information about:




More News Analysis
* Starwave security breach hits a nerve

* Online services, Web sites rake in retail bucks in marketing deals

* Netscape server bundles targets intranets, advanced network enterprises

* MCI earnings alert sparks BT probe

* Umax CEO says Apple needs a leader who knows the PC business

* Spamming lawyer gets disbarred

* GM gives wearable computer a test drive

* Frustrated NT users snap up third-party applications

* Motorola's DRAM decision bruises quarterly results but not share price

* Men in black (hats) identify future hacker targets: NT, intelligent hubs

* BackWeb acquires Lanacom, plans to integrate Headliner tool

* Seagate earns $59 million for quarter

* Yahoo beats analysts' predictions, posts a profit

* Netscape launches extranet for business-to-business sales and services

* Joint venture led by UUNet launches Internet business fax service

* Carmakers will let the Internet drive business-to-business network

* Justice Department approves merger of BT and MCI, with a few conditions

* EU issues declaration on Internet use

* NetFrame adds four-way Pentium Pro server

* NCR jumps on data mart bandwagon

* Europeans, U.S. remain at odds on encryption

* New face at the top of Apple as search for CEO begins

* Intranets outpace external Web sites' growth

* TechNet seeks to lobby Congress and boost U.S. education

* Bell Atlantic inks pact with MCI to link customers' LANs over long distances

* Sun's Enterprise JavaBeans specification on tap this month

* FileNet touts better-than-anticipated second-quarter results

* AMD earnings slump below expectations

* Compaq cuts expected to spark PC price war

* Control Data Systems to go private in $255 million deal

* Orioles give automated retail system a swing

* IBM licenses NDS for RS/6000, mainframes

* Online credit-card scare an inside job, Starwave says

* Amazon.com's quarterly loss less than expected, sales strong



index home News audio search help techcity computerworld

© Copyright 1997 by Computerworld, Inc. All rights reserved. @Computerworld is a service mark of International Data Group, Inc.