IE 7 Beta 2 (and matching DoS attack) released
Amazing, so today Microsoft releases Beta 2 of IE 7, and almost simultaneously comes a tailor made DoS attack! ”Overview: A denial of service vulnerability exists within Microsoft Internet Explorer 7.0 Beta 2 which allows for an attacker to cause the browser to crash, and or to execute arbitrary code on the targeted host. Technical Details: When running a specially crafted .html file, urlmon.dll inproperly parsers the ‘BGSOUND xsrc=file://—’ (approx. 344 dashes) and causes the crash. … Vendor Status: Microsoft was notified. Workaround: Mozilla Firefox.” If you are running IE 7 Beta 2 and want to give it a go, go to that link and construct the code, or simply click here for the proof of concept. I like how this comes up just after the zero day WMF flaw, and how it nicely dovetails into their “Trustworthy Computing” effort (emphasis on effort). ”Trustworthy Computing is a long-term, collaborative effort to provide more secure, private, and reliable computing experiences for everyone. This is a core company tenet at Microsoft and guides virtually everything we do. Trustworthy Computing is built on four pillars: Security, Privacy, and Reliability in our software, services, and products; and integrity in our Business Practices.” Sure, sounds like a game plan.
Tags: code, hacker, security
It’s just a beta..
Beta from a company about Microsoft should mean to watch out for stability, not security holes.
If something has security holes then it usually means that the company doesn’t have proper procedures.
f anyone wants help installing the workaround come to http://www.Freetechsupport.us and we will help you install firefox
Leave your response!
commentary »
Total borrowing from the Federal Reserve
What’s wrong with this picture? Can you say debt? Good, how about recession? Notice the gray areas, those are recession periods, we’ll wait for ours to appear here. Who thought it could get this bad this quickly? Here’s the graph at the Federal Reserve for you to research. Enjoy
humor »
HOWTO: send commandline email with attachments
Are you like me, do you have scripts running on servers and you need to know what they know? If there’s output in a file you can sed/grep/awk info out of them and have them emailed to you, but if you don’t know specifically what you’re looking for you may need the entire file/log/whatever. [...]
O'RLY? »
Equal Rights for All
Here’s a great, recent News of the Weird article,”Roy Hollander filed a civil rights lawsuit against Columbia University in New York City in August, claiming that its “women’s studies” curriculum teaches a religion-like philosophy that oppresses men by blaming them for nearly all social problems. (When interviewed by the New York Daily News, Hollander declined [...]
twitter-tweets »
Army: Twitter could be a terrorist tool
Hmmm…so the Army has claimed that terrorists may be ‘tweeting’ along to plan and organize attacks. Well yeah, I guess they could use Gmail, Slashdot comments and other things the same way, it seems their claim is that since this is more ‘real time’ it could be a danger. Ok, oh, and they [...]
sponsors »
get a student loan fast - compare loans in 2 clicks. good credit required.
we read »
be social »
we support »
tag cloud »
apple bands barack barack obama beer bsd cds code debian dubya election email features gamer hacker health hillary howto iphone lighttpd linux music muzak networking newstudy obama open source phishing politics privacy quote religion rock and roll security spam tech terror the daily show tour tv varnish video games vote web wiiRandom Posts
Latest Video Post
Most Commented
Most Popular