Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.![]() ![]() |
Apr 21 2008, 08:22 AM
Post
#1
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 11,013 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
QUOTE The many out there still using older versions of MSIE (such as Internet Explorer 5 or 6), might well be interested in two new vulnerabilities discovered and made public today on full disclosure. It looks somewhat like a Cross Site Request Forgery (CSRF) attack: A malicious URL you (somehow) hit. It can be unintentional on the user's part through e.g. an injected iframe on a forum. The URL tells the client to contact another server and does some bad things there that the user never intended, but had the authorization to do. The twist in this case is that the second hit doing damage can also be a FTP request, not just a HTTP request... http://isc.sans.org/diary.html?storyid=4126 -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2008 ![]() |
|
|
|
Apr 23 2008, 02:28 AM
Post
#2
|
|
|
Member ![]() ![]() Group: Members Posts: 81 Joined: 18-April 05 Member No.: 17,339 |
thank god. i'm with firefox!
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 5th July 2008 - 12:19 AM |