Help - Search - Members - Calendar
Full Version: Msie 5 And 6 Ftp Vulnerability (updated)
BleepingComputer.com > Security > Breaking Virus & Security News
   
quietman7
QUOTE
The many out there still using older versions of MSIE (such as Internet Explorer 5 or 6), might well be interested in two new vulnerabilities discovered and made public today on full disclosure.

It looks somewhat like a Cross Site Request Forgery (CSRF) attack: A malicious URL you (somehow) hit. It can be unintentional on the user's part through e.g. an injected iframe on a forum. The URL tells the client to contact another server and does some bad things there that the user never intended, but had the authorization to do. The twist in this case is that the second hit doing damage can also be a FTP request, not just a HTTP request...

http://isc.sans.org/diary.html?storyid=4126
jbravo
thank god. i'm with firefox!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.