Slashdot Mirror


IE 7.0/8.0b Code Execution 0-Day Released

SecureThroughObscure writes "Security blogger and researcher Nate McFeters blogged about a 0-day exploit affecting IE7 and IE8 beta on XP that was released by noted security researcher Aviv Raff. The flaw is a 'cross-zone scripting' flaw that takes advantage of the fact that printing HTML web pages occurs in the Local Machine Zone in IE rather than in the Internet Zone. Quoting McFeters's post: 'This is currently unpatched and in all of its 0-day glory, so for the time being, beware printing using the "print table of links" option when printing web pages.' McFeters and others will be presenting at Black Hat on the link between cross-site scripting and cross-zone. Rob Carter has been hitting this hard over at his blog, pointing out cross-zone weaknesses in Azureus, uTorrent, and the Eclipse platform."

3 of 131 comments (clear)

  1. Re:yes, I use it by stubear · · Score: 1, Offtopic

    Because he's a fucking dumbass and posted to the same story he moderated. Granted, not being allowed to comment in other threads simply because I've moderated one already is annoyingly stupid but if you moderate you know this, or should, by now.

  2. 0 Day on IE by misterhypno · · Score: 0, Offtopic

    Some random thoughts on this:

    IE - It Executed

    0 Day - 0 Productivity. Nothing works.

    So It Executed 0 Day and nothing works and there was no productivity.

    And ol Br'er Mac User, he jus' sits back and LAFFS!!

  3. Re:yes, I use it by Inda · · Score: 0, Offtopic

    To my siblings: Do people still reply to trolls?

    Oh wait...

    --
    This post contains benzene, nitrosamines, formaldehyde and hydrogen cyanide.