Microsoft Internet Explorer 4.x 5.x - Frame Loop Vulnerability
Advisory by USSR: "It is possible to create a malicious webpage that when visited by an IE user all of their system resources are devoured and depending on the system its possible that the machine can even crash and reboot itself."
Internet Explorer Security Pro
Internet Explorer Security is a utility that customizes aspects of the Internet Explorer Web browser.
The Register: Cumulative IE Patch for Maicious Cookies
A fairly serious flaw in Internet Explorer which would enable a malicious Web page or e-mail to drop a cookie containing an HTML script on a victim's machine and run it in the 'Local Computer' zone rather than the Internet zone to avoid restrictions has just been patched.
PivX Solutions: IE Allows Universal Cross Domain Scripting
"The object property of embedded WebBrowser controls is not subject to the Cross Domain security checks that embedded HTML documents ordinarily go through, and as such it is possible to escape any sandboxing and security zone restrictions."
The Register: IE, Outlook Run Malicious Commands Without Scripting
An attacker can run arbitrary commands on Windows machines with a simple bit of HTML, an Israeli security researcher has demonstrated. The exploit will work with IE, Outlook and Outlook Express even if active scripting and ActiveX are disabled in the browser security settings.
Wired News: IE Hole Surrenders Your Computer
An attacker can gain control of another user's machine using an HTML-formatted e-mail with an attachment that contains a small remote-control program. The e-mail can be sent directly to the victim, or can be placed on a website.
GreyMagic Security: Appendix to "IE allows universal Cross Site Scripting"
Explains how the "ANALYZE.DLG" resource can be manipulated to allow the execution of arbitrary code in the My Computer" zone.
The Register: Three New MS Security Holes - Two Nasty
Includes: MSXML may ignore IE security zone settings during a request for data from a Web site; and a VBscript problem which allows an attacker to read files on a victim's local drive, or eavesdrop on his browsing session.
Retrieving Information on Local Files in IE
Explains how the IMG element's dynsrc attribute can be exploited to test the existence of, find the size of, find the date last updated/modified of, and the creation date of, an arbitrary local file. By GreyMagic Security.
Privacy Secrets of MicroSoft's Internet Explorer
Security and internet privacy issues of Global Histories, Cookies, and Cache while browsing with Mac Explorer 5.0
More Security Sites
|