Latest IE Hole Lets Gopher Root You

CmdrTaco posted more than 12 years ago

Microsoft 567

rvaniwaa writes "Another hole in internet explorer has been discovered. This hole allows a hacker to root a user's computer whenever the user clicks on a gopher link. All versions of IE are affected and a Microsoft spokesman stated that the company is "moving forward on the investigation with all due speed""

cancel ×


Sorry! There are no comments related to the filter you selected.

My thoughts: (2, Insightful)

FortKnox (169099) | more than 12 years ago

Written in one of my journal entries [] .

See if this story follows pattern (I think it will).

Re:My thoughts: (-1, Troll)

Anonymous Coward | more than 12 years ago

You're right.

I must admit, I find Slashdot more useful for supporting my Windows users than my Linux users. For Windows, we get up-to-the minute bug alerts - sometimes faster than the mailing list I'm on (non-MS), for Linux we get... point oh minor build releases of kernels.

Whoopee doo... what a great site :o( Does this not go to show that in actual fact, Linux users are a bunch of boring geeks that get stroppy with people who are different and think that by reading other people's 'interesting' stories make them interesting too? This isn't true, but that's the impression I get.

Re:My thoughts: (-1, Troll)

MaxVlast (103795) | more than 12 years ago

No, that's actually about spot-on.

Re:My thoughts: (-1, Troll)

Anonymous Coward | more than 12 years ago

geeez... 7 downmods from all my past posts. Go editors!

Re:My thoughts: (1)

jeffy124 (453342) | more than 12 years ago

couldnt agree more with your comment "MS gets railed on for products that either no one (in the audience) has tried, or no one has tried for years."

Especially since the average web user wont run into gopher, that statement holds true. Even for non-average users, they still dont run into it. I think one comment asks how many people use it - three?

Too damn obvious (5, Funny)

CaseyB (1105) | more than 12 years ago

Let the "gopher hole" jokes begin.

Re:Too damn obvious (2, Funny)

Bob McCown (8411) | more than 12 years ago


Here's one []

Re:Too damn obvious (-1, Offtopic)

Anonymous Coward | more than 12 years ago

You mean like Richard Gere? No wait.. that was a hamster.

Re:Too damn obvious (1, Redundant)

garcia (6573) | more than 12 years ago

Dude, he said there would be 6 months before the next security hole was patched!

Re:Too damn obvious (1)

GrenDel Fuego (2558) | more than 12 years ago

Thinking about groundhogs?

Re:Too damn obvious (0, Troll)

purpledinoz (573045) | more than 12 years ago

I hope they plug this Gopher hole real fast.

Re:Too damn obvious (1)

InnereNacht (529021) | more than 12 years ago

Let me tell you, theres nothing worse than a hostile gopher hole.


IAgreeWithThisPost (550896) | more than 12 years ago

hatrisc (555862) | more than 12 years ago

Thud457 (234763) | more than 12 years ago

Not thursday yet (1, Funny)

Gyorg_Lavode (520114) | more than 12 years ago

Humm, it's early this week.

are there still any gpher severs out there? (0, Offtopic)

g0hare (565322) | more than 12 years ago

I haven't seen one in ages 1st post too

All three gopher links left.. (2, Interesting)

sphealey (2855) | more than 12 years ago

Speaking as a person who used to use gopher quite a bit - how many gopher links are left on the WWW? Three?


Re:All three gopher links left.. (5, Insightful)

linderdm (127168) | more than 12 years ago

I agree that there may not be many gopher links that look like gopher links, but what stops the malicious from disquising their gopher links to look like regular hrefs?

Re:All three gopher links left.. (2)

Jason Earl (1894) | more than 12 years ago

Of course if all you need to do to take over an IE users computer is run a gopher server and get some hapless schmoe to click on a gopher link you can bet there will be a sudden resurgence in this venerable protocol. I imagine mixing in a link in pornography spam would probably net you quite a few computers. Some of them would almost certainly have useful information.

Re:All three gopher links left.. (3, Interesting)

shadow303 (446306) | more than 12 years ago

Funny you should mention a resurgence. I just found this manifesto of people wanting to revive gopher. sto

Re:All three gopher links left.. (2)

zangdesign (462534) | more than 12 years ago

What would be the advantages of reviving gopher? I can't think of any.

Re:All three gopher links left.. (2)

Lord Omlette (124579) | more than 12 years ago

1. This is all the evidence Jon Katz needs to prove that Gopher is making a comeback and it's hackers like us who are doing it and we will overthrow the digerati and the ??AA and it could only be possible in a post 9/11 world.

2. Since gopher's used very rarely, if at all anymore, that's probably why MS hadn't bothered to keep the code up to date. /Gs isn't all it's cracked up to be :(

Re:All three gopher links left.. (5, Informative)

Simon Brooke (45012) | more than 12 years ago

Speaking as a person who used to use gopher quite a bit - how many gopher links are left on the WWW? Three?

That really isn't the point. It would not take many minutes to put up a gopher server with a Win 32 rootkit as content, and then put an innocent but interesting looking link into a web page ('free live world cup scores' would do nicely just now) with an href pointing to that server, and, ideally, one of those annoying JavaScript scrollers in the browser status display to prevent the user from noticing they're about to click a gopher link, and, hey! That's a few more suckers rooted. It will probably go through most firewalls, too.

If you (or your organisation) still use Internet Explorer, I would treat this as serious. Change your default IE install to have gopher point to a safe machine of your own; block gopher at your firewall; and, ideally, switch to Opera 6, Netscape 6, or Mozilla as your organisation's default browser.

This isn't going to be the last security hole found in IE.

Re:All three gopher links left.. (2)

Zocalo (252965) | more than 12 years ago

There are over a million Gopher links according to Google [] . Which, I have to admit, is a few orders of magnitude more than what I was expecting.

Hmm. Now I'm going all nostalgic for Archie, Veronica and WAIS. Well, maybe not WAIS.

Anonymous Coward | more than 12 years ago

Whistler's Mother (539004) | more than 12 years ago

youngerpants (255314) | more than 12 years ago

Gopher? (1)

TV-SET (84200) | more than 12 years ago

The fact that this bug was found makes me feel like someone is still using gopher. :) Haven't seen such person in a while myself.

More info... (-1, Troll)

Anonymous Coward | more than 12 years ago

here: Gopher hole [] .

hostile Gopher site? (4, Funny)

Fantanicity (583135) | more than 12 years ago

"hostile Gopher site"? Ouch ... I think shall wear kevlar underpants while using IE in future.

And how's that working for ya? (4, Funny)

jimmu (227057) | more than 12 years ago

From the article:

In January, Microsoft Chairman Bill Gates instructed employees to make software security a top priority.

Yeah, looks like everythings moving full steam ahead on that front.

Re:And how's that working for ya? (4, Insightful)

liquidsin (398151) | more than 12 years ago

Hey, cut them some slack. It only took five months to find a hole in a protocol that nobody's used, eight years? We should have all the IE/Outlook bugs patched up sometime around 2026.

...and yet (2)

rknop (240417) | more than 12 years ago

And yet, despite regular reports like this, posters on Slashdot keep asking why anybody who "cares about the web" would bother using a browser other than IE, and suggest that somebody who wants to use another browser (and, heavens, support cross-platfrom and cross-platfrom browsers) is a naive moralistic high-horse-rider who needs to wake up and get with the program.

With the program doesn't look like a very nice place to get to me....


Re:...and yet (2, Insightful)

Fantanicity (583135) | more than 12 years ago

When are the writers of other browsers going to release the documentation proving that the gopher handling code has been security auditted, that sufficient gopher testcases have been built, and that the browser passed all the gopher handling tests?

The reason there are aren't reports of security holes in gopher code in other browers is that no-one has looked, not that the holes don't exist.

Re:...and yet (0)

Anonymous Coward | more than 12 years ago

Another Micros**t employee!

**Sigh...** (2, Insightful)

TweeKinDaBahx (583007) | more than 12 years ago

Most of the other browsers have security holes found in them from time to time as well, but most of the kind crackers out there seems to take a diabolical pleasure in focusing on IE (and since it's one of the core technologies of it, Windows...). If people spent as much time trying to break many of the other Browsers out there, I'm sure they would find they're all their own brand of swiss cheese.

No software is rock solid, even when it's written to be. There's always a european teenager with way too much time on their hands just waiting to turn you Titanium fortress into a window screen...

Re:**Sigh...** (0)

Anonymous Coward | more than 12 years ago

european? Don't all teenage crackers come from Canada?

Re:...and yet (1)

rikkards (98006) | more than 12 years ago

<SARCASM> I find it funny that RedHat errata can come down the pipe and it never gets a main page posting. I mean sometimes I wonder if Microsoft is being isolated as a target for ridicule </SARCASM>
Granted Microsoft has not always been forthcoming with security alerts but hell even since 98 with WindowsUpdate you can more or less stay on top of these.

Trying not to get this modded as flamebait

New MS Hacker Slogan (5, Funny)

Anonymous Coward | more than 12 years ago

"Where do you want to gopher today?"

whoa! (-1, Offtopic)

Anonymous Coward | more than 12 years ago


Re:whoa! (-1, Offtopic)

hatrisc (555862) | more than 12 years ago

hmm.. as if first post! wasn't short enough, it's not fp! hehe.. i love slashdot

ObCaddyshack: (3, Funny)

kafka93 (243640) | more than 12 years ago

"I smell varmint poontang, and the only good varmint poontang is dead varmint poontang, I think."

Thank God (1, Offtopic)

Wind_Walker (83965) | more than 12 years ago

I'm just happy that it doesn't crash the browser when you click on a Dancing Hampsters [] .

And we all know (1, Funny)

TheDick (453572) | more than 12 years ago

How damn common those gopher links are, I click on hundreds per day, whatever am I going to do?

Use Archie!

Re:And we all know (0)

Anonymous Coward | more than 12 years ago

And we all know How damn common those gopher links are, I click on hundreds per day, whatever am I going to do?

Alright genious. How about if I set up a gopher server and send you a disguised link for turtle porn? I'm sure you'd be all over that link, and likewise, I'll have your r00t.


Honestly.... (1)

qurob (543434) | more than 12 years ago

Who the hell uses Gopher anymore, especialy 'doze newbies?

...on an almost regular basis (1)

LISNews (150412) | more than 12 years ago

"After being embarrassed on an almost regular basis by security flaws in its products -- including a debilitating problem found in its latest Windows XP operating system just days after its release -- Microsoft began a companywide training program on security issues earlier this year."


more holes (1)

lokor (574096) | more than 12 years ago

I can see thrue IE

On a vaguely related note (1)

Echemus (49002) | more than 12 years ago

What has happened to gopher?
Is there still a large number of gopher sites out there or has it really died a death having succumb to the "world wide web"?

I suppose it is why the bug wasn't discovered before. 90% of current Internet users probably never used gopher or have even heard of it.

Re:On a vaguely related note (1)

Quixotic Raindrop (443129) | more than 12 years ago

Actually, a lot of sites are still using gopher, in particular education, library, and government sites that simply make gopher:// accessible through an html file. I have run across a number of them while doing various kinds of academic research.

Sure, it's not as prevelant now as it was in 1991, but it still provides access to a fair amount of 'Net-accessible information.

well you can't expect... (5, Funny)

arson1 (527855) | more than 12 years ago

Well you can't expect Microsoft to keep up with all these new technologies and formats!

Wow... (2, Troll)

TweeKinDaBahx (583007) | more than 12 years ago

...I can only imagine how someone found this one.

However dangerous this hole may be, there are a few reasons why it probably won't create an end of the world scenario, most imporatant of these that gopher is absolutly archaic. I personally havn't seen a gopher server since 1996 (at MIT).

Second, as always, Microsoft will have a patch out fairly quickly, which is more that can be said for mozilla half of the time...

*Ducks and covers due to flying penguins*

Re:Wow... (1)

kafka93 (243640) | more than 12 years ago

All it takes is for someone to set up a dodgy gopher server to exploit the problem, send out a few thousand emails (or include a link or whatnot in an otherwise harmless outlook email virus, etc.) for this to become rather more of an issue.

Think of an "I love you" variant - "click on this link to pick up your card!", for example - and the problem quickly becomes larger.

Re:Wow... (1)

TweeKinDaBahx (583007) | more than 12 years ago

This is true, but I was just trying to make a point.

The guy who found this hole needs to go outside DURING THE DAY!


kids these days (1)

Jacer (574383) | more than 12 years ago

i've no clue what gopher is...........however i'd thank you kindly to stay away from MY gopher hole!

The remedy (5, Informative)

sh0rtie (455432) | more than 12 years ago

To protect from potential exploiting, you can temporarily disable the gopher
protocol like this:

Go to Tools -> Internet options -> Connections. Click on "LAN settings".
Check "Use a proxy server for your LAN". Click on "Advanced...".

Go to the Gopher text field
and enter "localhost", and "1" in the port field. This will stop Internet
Explorer from showing and processing any gopher pages.

this will protect you for now, at least until M$ pull their finger out

Or... (2, Insightful)

Robber Baron (112304) | more than 12 years ago

Don't use IE!

Re:Or... (0)

Anonymous Coward | more than 12 years ago

Too bad that I have to use MSIE at work - I'm sure I'm not the only one who has to, either.

Other remedy (0)

Anonymous Coward | more than 12 years ago

Press alt+F4 whenever the IE splash screen comes up.

fun (0)

Anonymous Coward | more than 12 years ago

so where's an exploit?

Yay I'M SAFE! (2, Funny)

ramdac (302865) | more than 12 years ago

I don't have a root user...this must mean my M$ machine is perfectly safe!?

Very funny. (1)

Ted Maul (582118) | more than 12 years ago

The sad thing is, so much stuff doesn't work on NT/2000/XP if you're not a local admin. How many apps out there feel the need to store their stuff in HKLM? Crap really.

Gopher? (1)

salsashrk (573024) | more than 12 years ago

Due to the currently proliferation of gopher sites still left on the internet, this could be the death knell for Microsoft!!

Seriously, why is this even newsworthy? It's like bitching that the Titanic might need the watertight compartment partitions to extend a little higher than E-Deck in the future..

Stats, anyone? (4, Interesting)

DesScorp (410532) | more than 12 years ago

Has anyone ever tried to compile stats on security holes in browsers? What I'd like to see is a comparison of browsers in this case, with each version listed with the various vulnerabilities found? Obviously, IE is going to come out on top here, but I'd be interested to see such a list anyway. I've looked around the SANS site and didn't see anything like that. I'd even settle for a short summary. Something like IE has X amount of holes, Netscape has Y amount of holes, Opera has Z amount, and so on.

Re:Stats, anyone? (5, Informative)

sh0rtie (455432) | more than 12 years ago

Yep this site specialises in just that
Here []

also George Guninski does some research here
Here []

and Mr Malware
Here []

just a routine (0)

OklaKid (552472) | more than 12 years ago

what a track record, M$ IE get its weekly updates, and it is closed source, like hiding sourcode will make it more secure heres proof that is a M$ lie...

Microsoft = Distrust (0)

way_out_on_the_dark_ (583525) | more than 12 years ago

When will people realize the true nature of Microsoft? Write dirty code quickly and cheaply just so they can wreap the riches when it is time to upgrade.

I still laugh every time I read this quote "In January, Microsoft Chairman Bill Gates instructed employees to make software security a top priority."

How can you make security a top priority when security has not been a priority for so long? Security is started at the lowest level and in the beginning and it is layered on as thick as you can. It is impossible to fix all the holes out there when you don't even know if the kernel is secure.

Scoop! (1)

UncleAlias (157955) | more than 12 years ago

There are still gopher links around!

Gopher, gopher.... (2, Funny)

mrgrey (319015) | more than 12 years ago

I think I read about that in one of my CS books....I recall the prof telling us not needing to retain the information.

Does this remind anyone of anything.. (0)

Anonymous Coward | more than 12 years ago

99 bugs in Explorer, no more, 99 bugs in the code, take one down, patch it around, 100 bugs in Explorer, no more.

100 bugs in Explorer, no more, 100 bugs in the code, take one down, patch it around, 101 bugs in Explorer, no more.

..and so on.

Jack Valenti == Mr. Burns (-1)

Thud457 (234763) | more than 12 years ago | (#3644966)

"My fellow Americans. As a young boy, I dreamed of being a baseball,
but tonight I say, we must move forward, not backward,
upward not forward,
and always twirling, twirling, twirling towards freedom.
-- Kodos gives a speech, "Treehouse of Horror VII"

Oz slang (0)

Anonymous Coward | more than 12 years ago

This article's title has a different meaning in Oz.

Test (1)

Fantanicity (583135) | more than 12 years ago

How does Slashdot display Gopher [] links?

Great! (2, Funny)

Ibjr (570729) | more than 12 years ago

A Gopher has rooted a hole in you! Wow, slashdot stories are funny again!

Online Solutions' page (3, Informative)

Radnor (4434) | more than 12 years ago

Here [] is the page from Online Solutions which details the bug, as well as a workaround and a gopher link to test IE's vulnerability.

If This Was Konqueror Instead of IE (-1)

egg troll (515396) | more than 12 years ago

If this hole had been found in an OpenSource browser instead of IE, the Slashbots would be all aflutter about how a dangerous bug was found since the source code was available. However, since its Microsoft lets be hypocrites and tear them apart. Sheesh.

well, thank goodness I got rid of win2k (-1, Offtopic)

orKiD (56535) | more than 12 years ago

It's all linux on my machine, and I'm learning quickly that the MS way is not the only way. Even though it's tough adjusting, I bet I can do it :)

No more viruses though!

Moving at the speed of business (molassas) (0)

Anonymous Coward | more than 12 years ago

A Microsoft spokesman who refused to be identified said Tuesday that the company is "moving forward on the investigation with all due speed" and will take the action that best serves its customers.


Although Gopher is considered an outdated format for Internet content, it is still supported by Internet Explorer and most other browsers.


And the spokesman added, "Responsible security researchers work with the vendor of a suspected vulnerability issue to ensure that countermeasures are developed before the issue is made public and customers are needlessly put at risk."

I wonder if they knew about this when gopher was new, but just never got around to patching it?

Mosaic Bug? (2)

cybermage (112274) | more than 12 years ago

The article says this affects all versions of IE. I wonder if this hole dates all the way back to NCSA Mosaic. It'd be pretty funny if the hole is that old.

If this is, in fact, a NCSA Mosaic bug, it probably exists in Netscape thru version 4.x as well. I'd be pretty surprised if either company felt the need to alter the gopher code while they were busy fighting over http.

Ah the memories (1)

nurb432 (527695) | more than 12 years ago

UUCP, Gopher, Archie.. Those were the days :)

Didnt know anyone was left out there in 'gopherspace'..

URL of ANY gopher site al all? (0)

Anonymous Coward | more than 12 years ago

I have never seen one.
What does the URL look like?

Omg... (1)

SkyLeach (188871) | more than 12 years ago

I hear that Elton John was starting a movement to protest the patching of this M$ "feature" before someone explained what "gopher" and "root" really ment.

Reminicent of the CHARGEN port problem (2)

iceT (68610) | more than 12 years ago

Anyone remember the CHARGEN problem with IE3? Connect to the CharGen port, and IE would read and cache (in memory) until the PC crashed?

It's fun when MS figures out something new for the Internet...

Message from Osama to Mr..Gates (2)

AftanGustur (7715) | more than 12 years ago

I love your stuff []

Gopher (-1)

Sadlly... (2)

C0vardeAn0nim0 (232451) | more than 12 years ago

now seriously, this is getting anoying. since I started to rely on mozilla only (or since I ditched netscape 4.x for good) some 6 months ago I saw only ONE serious security flaw reported on it and it was corected in a week or so. but with IE we have at least 2 anoucements a month. this is getting so frequent I'm here asking /. to only publish news about IE when the head line is someting in the lines of the's style headline above. It'd save a lot in terms of my patience and bandwidht.

Slipping off the treadmill (2)

babbage (61057) | more than 12 years ago

The last gopher server I used to visit regularly shut down something like three years ago. As far as I know -- no, I haven't checked -- there are no active gopher servers anymore.

And Microsoft is just getting around to hunting down security holes *now*? What does this say about more current protocols?

I predict that by 2005, they'll start looking for holes in SOAP )

Internet Sieve (1)

lionchild (581331) | more than 12 years ago

At what point do we shift the name of a product like this from Explorer to Sieve? How many previous 'security holes' have there been?

MS is starting to look more and more like the little boy whose plugging the leaks in the dike with their fingers.

CaddyShack (2)

tswinzig (210999) | more than 12 years ago

Sandy: "I want you to kill all the gophers on this course."

Spackler: "Check me if I'm wrong Sandy, but if I kill all the golfers, they'll lock me up and throw away the key."

Sandy: "The GOPHERS, man! Kill all the GOPHERS!"

New Product: Microsoft Door (2, Funny)

Ghengis (73865) | more than 12 years ago

Keep the burglars out of your house with the new Microsoft Door. Complete with not dead-bolts, but tape, yes TAPE to keep it locked. Also, we've reached an all new level of user friendliness with the omission of door-knobs!!!

When was the last time... (2)

istartedi (132515) | more than 12 years ago

...anybody clicked on a gopher link?

If there isn't a patch yet, or if MSFT says you gotta have IE6 or something, easiest thing to do is just block gopher. What is the gopher port anyway?

yet another reason... (1)

tps12 (105590) | more than 12 years ago


Official Bugtraq Post (5, Informative)

PunchMonkey (261983) | more than 12 years ago

The Official Bugtraq Post:


Gopher is a protocol developed at the University of Minnesota in the
early 1990's. Gopher servers offer hierarchically organized directories
and files. These form a "gopherspace" which can be thought of as the
predecessor of the World Wide Web. Gopher was mostly abandoned soon after
HTTP and the World Wide Web started gaining popularity.

Microsoft Internet Explorer has a built-in gopher client. Gopher pages can
be accessed via URLs starting with "gopher://". The part of code in IE
which parses gopher replies contains an exploitable buffer overflow
bug. A malicious server may be used to run arbitrary code on an IE user's


When the overflow is triggered, a fixed sized buffer in stack gets
overwritten with data from the gopher server. This data can contain most
octets from 0 to 255 (also nulls) which makes it particularly easy to
inject a working shellcode in it. This is a traditional, trivially
exploitable buffer overflow. A test exploit has been successfully used to
run arbitrary code without user intervention with various IE versions and
systems including IE 5.5 and 6.0.

The attack can be launched via a web page or an HTML mail message which
redirect the user to a malicious gopher server when the victim views them.
The server can be very minimal, ie. a program that can listen on a TCP
port and write a block of data; a fully operational gopher server isn't
necessary in order to carry out the attack.

The exploiter could do anything that a regular user could do on the
system: retrieve, install, or remove files, upload and run programs, etc.

Full technical details aren't disclosed at this time to prevent


Internet Explorer users can protect themselves from the flaw by disabling
the gopher protocol. Barely any gopher servers exist on the Internet
today, so this is unlikely to cause problems. If needed, a gopher client
or some other web browser can be used to access the gopherspace.

An easy way to disable processing and displaying gopher pages is to define
a non-functional gopher proxy in Internet Options. Select Tools ->
Internet options -> Connections. Click on "LAN settings". Check "Use a
proxy server for your LAN". Click on "Advanced...". Here you can define
proxy servers to be used with different protocols. Go to the Gopher text
field and enter "localhost", and "1" in the port text field. This will
stop Internet Explorer from fetching any gopher documents.

After installing the patch from Microsoft you can remove these gopher
proxy settings (or restore them to values they had before).

For more information and a vulnerability test see


Microsoft was contacted on May 20th. At the moment of writing this
advisory, Microsoft has started designing and coding a fix, but hasn't
given any approximation of when it would be released. The patch will be
available at asp

when it is completed.

URL for technical info on the hole (1)

Knytefall (7348) | more than 12 years ago

This site [] contains technical info on the hole. It's a buffer overflow.

Workaround (2)

DeadSea (69598) | more than 12 years ago

Is there a workaround for this? Probably not. I don't think any of the major browsers have a way to selecivly disable browser features. It would be nice if you could disable gopher: hyperlinks until this got fixed.

A nice browser feature would be a regular expression based prefilter of web pages. If a file called prefilter.rules exists, the browser would run the raw html of each pages it downloaded through the filter. This would allow admins to make the browser safe again (with some lost functionality) until the browser was patched.

In this case you might want to use a rule something like:
s/(gofer\:[^'" \n\r\t]*)/about:blocked.html?$1/

I should see if this is a requested feature for mozilla yet. With browsers knowing about regexp for javascript this probably wouldn't be too hard to implement. Plus once it was implemented, you could use it for blocking ads and other annoyances.

