Slashdot Mirror


New URI Browser Flaws Worse Than First Thought

narramissic writes "URI (Uniform Resource Identifier) bugs have become a hot topic over the past month, since researcher Thor Larholm showed how a browser could be tricked into sending malformed data to Firefox. Now, security researchers Billy Rios and Nathan McFeters say they've discovered a number of ways attackers could misuse the URI protocol handler technology to steal data from a victim's computer. 'It is possible through the URI to actually steal content form the user's machine and upload that content to a remote server of the attacker's choice,' said McFetters, a senior security advisor for Ernst & Young Global Ltd. 'This is all through functionality that the application provides.'"

3 of 149 comments (clear)

  1. Not anonymous!!!!!! by brindafella · · Score: 0, Offtopic

    I am NOT anonymous!!! And, perhaps the first to say so!!!!

    --
    Looking at space, radio, science and computing from a 'down-under' amateur enthusiast perspective.
  2. 202c by unforkable · · Score: 0, Offtopic

    Thus some regular expressions are verboten in Guermany !

  3. My Nephew has to choose his major soon by infonography · · Score: 0, Offtopic

    He has been in Preschool now for 5 months. Pretty soon they will want him to pick either Arts (Fingerpainting or Crayon), Science (Frogs) or Culinary Arts (Mudpies).

    Life is tough for the modern Two Year Old.

    --
    Sorry about the writing. Robot fingers, you know? Cliff Steele in DOOM PATROL #23