OT: IE flawed? NO!, you don't say, important security info |
|
Porsche, and the Porsche crest are registered trademarks of Dr. Ing. h.c. F. Porsche AG.
This site is not affiliated with Porsche in any way. Its only purpose is to provide an online forum for car enthusiasts. All other trademarks are property of their respective owners. |
|
OT: IE flawed? NO!, you don't say, important security info |
tat2dphreak |
Jul 2 2004, 09:49 AM
Post
#1
|
stoya, stoya, stoya Group: Benefactors Posts: 8,797 Joined: 6-June 03 From: Wylie, TX Member No.: 792 Region Association: Southwest Region |
http://www.internetnews.com/security/artic...cle.php/3374931
I switched over to firefox and changed all my passwords... damn M$ !!! |
Part Pricer |
Jul 9 2004, 06:28 AM
Post
#2
|
Believe everything I post Group: Benefactors Posts: 1,825 Joined: 28-December 02 From: Danbury, CT Member No.: 35 |
I know that I recommended that you look at using a different browser than IE. Now, to show you that you are never safe and must always be vigilant.
QUOTE A popular browser for Windows is subject to a security hole that creates a means for hackers to run malicious code on vulnerable machines. But this time, the vulnerability involves Mozilla and Firefox browsers - not Internet Explorer. Security researchers have discovered that users could be attacked by hackers using a bug in how Mozilla and Firefox handle the "shell:" function in windows. The function enables websites to invoke various programs associated with specific extensions. But flaws in Mozilla's implementation create a way for a skilled hacker to execute arbitrary code on vulnerable Windows machines. Information on the bug was posted onto a full disclosure security mailing list earlier this week. The flaw affects Mozilla and Firefox on Windows XP or Windows 2000 only. The Mozilla Foundation yesterday issued a patch that resolves the flaw by disabling the use of the shell: external protocol handler. Alternatively users are advised are advised to update their systems to the latest version of Mozilla (1.7.1), Firefox (0.9.2). Users of Thunderbird, Mozilla's next generation e-mail client, also need to upgrade to version 0.7.2 of the software. Firefox is a preview of Mozilla's next generation browser. Thunderbird is Mozilla's email client. Security firm Secunia rates the problem as "moderately critical". So it’s less serious than still unresolved issues bedevilling IE but still unwelcome to Windows users defecting from IE for security reasons. Secunia notes that multiple exploits in Internet Explorer also utilise "shell:" functionality. "The shell: URI handler is inherently insecure and should only be accessed from a few trusted sites - or not from a browser at all," it says. Here is the link to the update instructions and the downloads: http://mozilla.org/security/shell.html |
Lo-Fi Version | Time is now: 27th December 2024 - 12:57 PM |
All rights reserved 914World.com © since 2002 |
914World.com is the fastest growing online 914 community! We have it all, classifieds, events, forums, vendors, parts, autocross, racing, technical articles, events calendar, newsletter, restoration, gallery, archives, history and more for your Porsche 914 ... |