Welcome to p2pnet.net - The original daily p2p and digital news site. Always First!
REGISTER | LOGIN
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
Reviews
Open Source
Mobiles
Advertising
Products
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Scroogle Search: 
Search
 
Web p2pnet   
Search: 
Search
Torrent Site Tracker
    Sponsored by
Frostwire
 
p2pnet
 


mp3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

New Microsoft IE security flaw

p2pnet.net News:- “Greyhats Security Group is back and we’re ready to kick the crap out of sp2 :) ,” said Paul on SecurityFocus’ Bugtraq archive, last month.

Now, he’s reporting a security problem in Microsoft’s Internet Explorer browser which allows attackers to build a fake site that looks exactly like a real one.

Or, as Secunia phrases it, the “moderately critical” vulnerability, “can be exploited by malicious people to conduct sophisticated cross-site scripting attacks against any web site”.

The flaw is the result of an error in the DHTML Edit ActiveX control when handling the "execScript()" function in certain situations, says Secunia, going on:

“This can be exploited to execute arbitrary script code in a user’s browser session in context of an arbitrary site.

Secunia has constructed a test, which can be used to check if your browser is affected by this issue: http://secunia.com/internet_explorer_cross-site_scripting_vulnerability_test/

“The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2.”

Solution?

Set your security level to high for the "Internet" zone (disable ActiveX support), suggests Secunia.

===================

See:-
real oneInternet Explorer DHTML Edit ActiveX Control Cross-Site Scripting, December 16, 2004

HOME

Leave a Reply

ONLY items referencing the post at hand, please. No links to personal sites, no personal attacks, trolling, freebie advertising, or off-topic posts. Thanks. And Cheers!

    Sponsored by
tek savvy