TECH.BLORGE.com
VISTA.BLORGE.com
MAC.BLORGE.com
GAMER.BLORGE.com

July 24, 2007 |

LinkedIn IE toolbar security bug uncovered

By Arnold Zafra





LinkedInIEtoolbarsecuritybugdiscoveredWith the popularity of social networking sites continuing to increase, they have become the target of online predators and criminals. Now VDA Labs researchers have found a vulnerability in the LinkedIn IE toolbar, version 3.x.

While the proof-of-concept code posted by researchers Jared DeMott and Justin Seitz on the VDA Labs website will not compromise a user’s system, security research firm Secunia classified the LinkedIn IE Toolbar security flaw as extremely critical. 

The vulnerability is caused due to an error within the IEToolbar.IEContextMenu.1 (LinkedInIEToolbar.dll) when handling the “Search()” method, which takes in a VARIANT as the “varBrowser” argument.

Thus, when a user visits a malicious website, hackers can exploit the user’s system through this security hole.

To block this security vulnerability, Seconia suggests to set the “kill-bit” for the affected ActiveX Control, but PC World’s Stuart Johnston cautions that doing so would entail editing the Windows Registry. If done incorrectly, users might damage the Windows installation and re-installation might be needed.

So, if you are an IE user who installed the LinkedIn Toolbar, better disable it now until such time that a patch is released.

Related:

  • LinkedIn Platform: Killing itself with closed
  • LinkedIn says no to Facebook garbage
  • New Google Toolbar saves settings online
  • LinkedIn wants its slice of the Display Advertising pie
  • LinkedIn improves search, still no platform




  • Sign up for the BLORGE daily email newsletter

    One Response to “LinkedIn IE toolbar security bug uncovered”

    1. Mario Sundar:

      Hi Arnold,

      I’m the Community Evangelist at LinkedIn. We just rolled out a fix that was pushed out to all IE Toolbar users. The fix is forced upon users, else the toolbar shuts down.

    Leave a Reply:

    Copyright © 2008 Engaging and compelling blogs that entertain and inform