Slashdot Mirror


MSN, Word Vulnerable To Shell: URI Exploit

LnxAddct writes "InfoWorld is reporting that a few Microsoft products are also vulnerable to the "shell:" scheme vulnerability found in Mozilla last week. These applications include Microsoft Word and MSN Messenger."

4 of 392 comments (clear)

  1. I have this to say about that... by Anonymous Coward · · Score: -1, Troll

    give.........it.........up.

  2. Mac's safer if no MS code on them by Anonymous Coward · · Score: -1, Troll

    In my 20+ years of using a Mac and getting only one virus, I can tell you how I did it, I ran as little Microsoft code as humanly possible.

    I'm in IT, I'm 50 and I don't have any grey hair.

    What's your story?

  3. LINUX HYPOCRITES by GISGEOLOGYGEEK · · Score: -1, Troll

    Well here you go,

    Looks like you all ignored the article posted a couple days ago describing the Mozilla problem.

    Remember? ... the one where nearly everyone here put the blame totally on MS, that Mozilla was in no way to blame even though it was Mozilla passing the dangerouse commands to windows.

    I laid out how it is, how you hypocrites do it:

    problem with MS, blame MS.
    problem with anything Linux, blame MS.

    And you fools have proven it beyond doubt on this thread.

    You can't have it both ways. If the Mozilla problem wasn't really a problem, then it can not be called a problem for these MS products for exactly the same reason.

    --
    George Bush + Linux = "I will not let information get in the way of the fight against Windows"
  4. Re:Misinformation... by Nevo · · Score: 0, Troll

    Actually, to a large extent, Microsoft is right here. It's no secret that as soon as a patch is released, the bad guys diff the new and old versions of the file to see what changed, which leads them right into creating an exploit.

    Without the diff, it's a LOT (and I do mean a *lot*) harder for the population at large to create these attacks.

    To a very large extent, there ARE no malicious attackers when the fix gets out before word of the exploit does.