|
Article on other languages:
|
Microsoft Internet Explorer 6 (commonly abbreviated to IE6), is a graphical web browser developed by Microsoft and included as part of the Microsoft Windows XP and Windows Server 2003 lines of operating systems. It was the most widely used web browser during its tenure (surpassing Internet Explorer 5.x), attaining a peak of about 95% usage share during 2002 and 2003 when it began steadily declining until 2007 when it rapidly lost market share to Windows Internet Explorer 7. microsoft internet explorer 6.0 was released on August 27, 2001, shortly after Windows XP was finished. This version included DHTML enhancements, content restricted inline frames, and partial support of CSS level 1, DOM level 1 and SMIL 2.0.[2] The MSXML engine was also updated to version 3.0. Other new features included a new version of the Internet Explorer Administration Kit (IEAK), Media bar, Windows Messenger integration, fault collection, automatic image resizing, P3P, and a new look-and-feel that was in line with the "Luna" visual style of Windows XP, when used in Windows XP. In 2002, the Gopher protocol was disabled and support for it was dropped in Internet Explorer 7.[3] In a May 7, 2003 Microsoft online chat, Brian Countryman, Internet Explorer Program Manager, declared that on Microsoft Windows, Internet Explorer would cease to be distributed separately from the operating system (IE 6 would be the last standalone version);[4] it would, however, be continued as a part of the evolution of the operating system, with updates coming only bundled in operating system upgrades. Thus, Internet Explorer and Windows itself would be kept more in sync. However, after one release in this fashion (6.0 Service Pack 2 in August 2004), Microsoft changed its plan and released Internet Explorer 7 for Windows XP SP2 and Windows Server 2003 SP1 in late 2006. IE6 remained more popular than its successor in business use for more than a year after IE7 came out. [5] A DailyTech article noted, "A Survey found 55.2% of companies still use IE 6 as of December 2007", while "IE 7 only has a 23.4 percent adoption rate". [6]
Overview & Security IssuesAs of May 28, 2006, Secunia reports 104 vulnerabilities in Internet Explorer, 18 of which are unpatched, some of which are rated moderately critical in severity[7]. In contrast, Mozilla Firefox, the main competitor to Internet Explorer, is reported to have only 34 security vulnerabilities, of which 3 remain unpatched and rated less critical[8]. Opera, another competitor to Internet Explorer, has 15 vulnerabilities and none of them remain unpatched[9]. Although security patches continue to be released for a range of platforms, most recent feature additions and security improvements were released for Windows XP only. As of June 23, 2006, security advisory site Secunia counted 20 unpatched security flaws for Internet Explorer 6, many more and older than for any other browser, even in each individual criticality-level, although some of these flaws only affect Internet Explorer when running on certain versions of Windows or when running in conjunction with certain other applications.[10] On June 23, 2004, an attacker using compromised Internet Information Services 5.0 Web servers on major corporate sites used two previously undiscovered security holes in Internet Explorer to insert spam-sending software on an unknown number of end-user computers.[11] This malware became known as Download.ject and it caused users to infect their computers with a back door and key logger merely by viewing a web page. Infected sites included several financial sites. Probably the biggest generic security failing of Internet Explorer (and other web browers too) is the fact that it runs with the same level of access as the logged in user, rather than adopting the principle of least user access. Consequently any malware executing in the Internet Explorer process via a security vulnerability (e.g. Download.ject in the example above) has the same level of access as the user, something that has particular relevance when that user is an Administrator. Tools such as DropMyRights are able to address this issue by restricting the security token of the Internet Explorer process to that of a limited user. However this added level of security is not installed or available by default, nor does it offer a simple way to elevate privileges ad-hoc when required (for example to access Microsoft Update) Art Manion, a representative of the United States Computer Emergency Readiness Team (US-CERT) noted in a vulnerability report that the design of internet explorer 6 service pack 1 made it difficult to secure. He stated that:
Manion later clarified that most of these concerns were addressed in 2004 with the release of Windows XP Service Pack 2, and other browsers have now begun to suffer the same vulnerabilities he identified in the above CERT report.[13] Many security analysts attribute Internet Explorer's frequency of exploitation in part to its ubiquity, since its market dominance makes it the most obvious target. However, some critics argue that this is not the full story; the Apache HTTP Server, for example, had a much larger market share than Microsoft IIS, yet Apache has traditionally had fewer (and generally less serious) security vulnerabilities than IIS.[14] In an October 2002 interview, Microsoft's Craig Mundie admitted that Microsoft's products were "less secure than they could have been" because it was "designing with features in mind rather than security."[15] IIS 6 has changed this, however; Secunia has only two vulnerabilities listed for the first three years since its release,[16] compared with 15 for Apache 2.0 in the same time period.[17] As a result of its many problems, some security experts, including Bruce Schneier, recommend that users stop using Internet Explorer for normal browsing, and switch to a different browser instead.[18] Several notable technology columnists have suggested the same, including the Wall Street Journal's Walt Mossberg,[19] and eWeek's Steven Vaughan-Nichols.[20] On July 6, 2004, US-CERT released an exploit report in which the last of seven workarounds was to use a different browser, especially when visiting untrusted sites.[21] Patches CriticismA common criticism of Internet Explorer is of the speed at which fixes are released after discovery of the security problems, and in some circumstances, the problems not always being completely fixed. For example, after Microsoft released patches to close holes in its Windows NT line of operating systems on February 2, 2004, 200 days after their initial report, Marc Maifrett, Chief Hacking Officer of eEye Digital Security, is quoted in a cNet article as saying:
The same article quoted @stake's Chris Wysopal, vice president of research and development as saying:
The Register criticized Maifrett for publicizing a security hole leading to the creation of the Code Red worm, arguing that:
Microsoft attributes the perceived delays to rigorous testing. The testing matrix for Internet Explorer demonstrates the complexity and thoroughness of corporate testing procedures. A posting to the Internet Explorer team blog on August 17, 2004 explained that there are, at minimum, 234 distinct releases of Internet Explorer that Microsoft supports (covering more than two dozen languages, and several different revisions of the operating system and browser level for each language), and that every combination is tested before a patch is released.[24] In May 2006, PC World rated Internet Explorer 6 the eighth worst tech product of all time. [25] Security framework
Patches and updates to the browser are released periodically and made available through Windows Update web site. Microsoft's recent Windows XP Service Pack 2 adds several important security features to Internet Explorer, including a popup blocker and additional security for ActiveX controls. ActiveX support remains in Internet Explorer although access to the "Local Machine Zone" is denied by default since Service Pack 2. However, once an ActiveX control runs and is authorized by the user, it can gain all the privileges of the user, instead of being granted limited privileges as Java or JavaScript do. This was later solved in the Windows Vista version of IE 7, which supported running the browser in a low-permission mode, making malware unable to run unless expressly granted permission by the user. Windows adoption capabilityInternet Explorer 6.0 supports Windows NT 4.0, Windows 98, Windows 2000, Windows Me, Windows XP and Windows Server 2003 but not Windows 95. The Service Pack 1 update supports all of these versions, but Security Version 1[1] is only available as part Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1 (and 2). However, Windows Vista is not supported, and once XP SP2 is upgraded to IE7, uninstalling without a system restore is not supported. See Removal of Internet Explorer for information relating uninstalling IE. Release history
ExtendedShdocvw.dll version numbers plus related notes.[26]
References and notes
See alsoExternal links
Article keywords: internet explorer 6 service pack 1, |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
This article is from Wikipedia. All text is available under the terms of the GNU Free Documentation License.
Mercedes Car
This site monitored by SitePinger.net