Slashdot Mirror


Gaping Holes In Fully Patched IE7, Firefox 2

Continent1106 writes "Hacker Michal Zalewski has ratcheted up his ongoing assault on Web browser security models, releasing details on serious flaws in fully patched versions of IE6, IE7 and Firefox 2.0. The vulnerabilities could cause cookie stealing, page hijacking, memory corruption, code execution, and URL bar spoofing attacks." Here is Zalewski's post to Full Disclosure.

7 of 303 comments (clear)

  1. And Opera by Constantine+XVI · · Score: -1, Troll

    No holes for Opera? Oh well...

    (sits back in corner with large grin on face)

    --
    "I think an etch-a-sketch with an ethernet port would beat IE7 in web standards compliance."
    1. Re:And Opera by Anonymous Coward · · Score: -1, Troll

      Opera you say?

  2. What about Flock? by ringfinger · · Score: 0, Troll

    Anyone have info on how stacks up to IE/FF? http://30days.itious.com/

  3. Re:Go old NoScript by MightyYar · · Score: 0, Troll

    I wish NoScript were the default behavior.

    --
    W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
  4. Psst... Hey Slashdot, your bias is showing by Anonymous Coward · · Score: -1, Troll

    And once again, Slashdot fails to mention that the exploit does not work if you are using Vista and IE7.

    I guess they can't afford to admit how Firefox is old crap, so they keep failing to mention when the one-two punch combo of Vista and IE knocks them on their asses. Again. And again.

  5. Plug it by Anonymous Coward · · Score: -1, Troll

    So, is this the solution? Plug that hole.

  6. Re:Nice Bit of Trolling by jp10558 · · Score: 0, Troll

    I'm pretty sure that CSS is faster and more efficient (as you don't have to redownload the whole thing every time - and there were several stories that said it would save /. lots of bandwidth charges) for any browser made in the last, what - 7 years?

    --
    Opera, Proxomitron-Grypen,GPG 0x0A1C6EE3