13-07-2004, 19:32
|
#1
|
|
Google it!!
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL
BT Telephone
Posts: 14,949
|
Here we go again with IE
From
Secunia
4 new vulnerabilities found in Internet Explorer
Quote:
1) It is possible to redirect a function to another function with the same name, which allows a malicious website to access the function without the normal security restrictions.
Successful exploitation allows execution of arbitrary script code in the context of another website. This could potentially allow execution of arbitrary code in other security zones too.
2) Malicious sites can trick users into performing actions like drag'n'drop or click on a resource without their knowledge. An example has been provided, which allows sites to add links to "Favorites". However, resources need not be links and the destination could be different than "Favorites".
This issue is a variant of an issue discovered by Liu Die Yu.
SA9711
http-equiv has posted a PoC (Proof of Concept), which combined with the inherently insecure Windows "shell:" functionality, can be exploited to compromise a vulnerable system.
3) It is possible to inject arbitrary script code into Channel links in Favorites, which will be executed when the Channel is added. The script code is executed in Local Security Zone context.
4) It is possible to place arbitrary content above any other window and dialog box using the "Window.createPopup()" function. This can be exploited to "alter" the appearance of dialog boxes and other windows.
|
|
|
|
13-07-2004, 20:53
|
#2
|
|
cf.geek
Join Date: Jun 2003
Location: Farnham
Posts: 503
|
Re: Here we go again with IE
I'm fed up with all these unpatched IE security flaws. Microsoft is clearly not on top of the problem. So I've installed Mozilla 1.7.1 and the Orbit 3+1 theme.
Alan
|
|
|
13-07-2004, 20:57
|
#3
|
|
Google it!!
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL
BT Telephone
Posts: 14,949
|
Re: Here we go again with IE
Oooh theme? Linky? Please  I'm running Noia 2.0 here
|
|
|
13-07-2004, 21:00
|
#4
|
|
cf.geek
Join Date: Jun 2003
Location: Farnham
Posts: 503
|
Re: Here we go again with IE
It was on the mozilla website, so isn't exactly hidden under a bushel
http://themes.mozdev.org/themes/orbit.html
|
|
|
13-07-2004, 21:06
|
#5
|
|
Google it!!
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL
BT Telephone
Posts: 14,949
|
Re: Here we go again with IE
Shame I'm running firefox and it doesn't seem to think its compatible because that theme looks nice
|
|
|
13-07-2004, 21:13
|
#6
|
|
cf.geek
Join Date: Jun 2003
Location: Farnham
Posts: 503
|
Re: Here we go again with IE
Pity, I'm intending to put firefox on my notebook, so as to patch the security on that. Do you know whether firefox is smaller & faster than mozilla, coz my notebook is old and slow.
Alan
|
|
|
13-07-2004, 21:20
|
#7
|
|
Google it!!
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL
BT Telephone
Posts: 14,949
|
Re: Here we go again with IE
4.7 mb download compared to 21mb for mozilla but its only the browser application and not an email tool too, seems to run nicely for me on my system.
http://www.mozilla.org/download.html for a comparrison of file sizes etc
|
|
|
13-07-2004, 21:23
|
#8
|
|
cf.geek
Join Date: Jun 2003
Location: Farnham
Posts: 503
|
Re: Here we go again with IE
Looks just the ticket. Going upstairs to fire up notebook.
Cheers
Alan
|
|
|
13-07-2004, 21:23
|
#9
|
|
Google it!!
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL
BT Telephone
Posts: 14,949
|
Re: Here we go again with IE
Oh and http://www.mozilla.org/products/fire...uirements.html gives the requirements for running firefox 
Firefox
Quote:
Windows
Operating Systems
* Windows 98
* Windows 98SE
* Windows ME
* Windows NT 4.0
* Windows 2000
* Windows XP (Recommended)
Minimum Hardware
* Pentium 233 MHz (Recommended: Pentium 500MHz or greater)
* 64 MB RAM (Recommended: 128 MB RAM or greater)
* 52 MB hard drive space
|
Mozilla
Quote:
Windows
Operating Systems
* Windows 95
* Windows 98
* Windows 98SE
* Windows ME
* Windows NT 4.0
* Windows 2000
* Windows XP
Minimum Hardware
* Pentium 233 MHz
* 64 MB RAM
* 52 MB hard drive space
|
|
|
|
13-07-2004, 23:01
|
#10
|
|
cf.geek
Join Date: Jun 2003
Location: Farnham
Posts: 503
|
Re: Here we go again with IE
This old notebook doesn't meet the minimum spec in practically all the measures, being Win95 90MHz 40MB RAM machine, which will be ten years old next year, but both firefox 9.2 & mozilla 1.7.1 appear to work, albeit rather slowly. I only use this clunker for email & low bandwidth web, neither of which are very demanding, but suspect i might have to get a new machine sometime in the next ten years
/Edit Firefox takes about 3 times longer then IE to load a page on this machine, probably because I'm running out of physical memory - but there's not much that can be done about that - looks like IE for known safe sites & Firefox for more general browsing.
Last edited by Alan Waddington; 13-07-2004 at 23:11.
|
|
|
14-07-2004, 17:58
|
#11
|
|
I am not a geek!
Join Date: Jul 2003
Posts: 1,395
|
Re: Here we go again with IE
Quote:
|
Originally Posted by Alan Waddington
This old notebook doesn't meet the minimum spec in practically all the measures, being Win95 90MHz 40MB RAM machine, which will be ten years old next year, but both firefox 9.2 & mozilla 1.7.1 appear to work, albeit rather slowly. I only use this clunker for email & low bandwidth web, neither of which are very demanding, but suspect i might have to get a new machine sometime in the next ten years 
|
If pretty graphics don't bother you, you could try Lynx which is a text based web browser. It's small and very fast, some pages can be difficult to decipher in it but it's great for quick web access. I use it on my old 486 laptop for reading online novels.
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 12:27.
|