Full Disclosure mailing list archives
RE: How big is the danger of IE?
From: "Larry Seltzer" <larry () larryseltzer com>
Date: Thu, 8 Jul 2004 21:32:39 -0400
...the security zone model itself (well, at least its implementation in IE, etc) _is
the problem_ and can often be exploited independent of the scritping, and other active content processing, state of the zone in which some arbitrary piece of HTML is rendered. So you can do a cross-zone attack against the restricted zone, with all scripting and active content disabled? I'd like to see an example of this. Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blog.ziffdavis.com/seltzer larryseltzer () ziffdavis com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- How big is the danger of IE? Yaakov Yehudi (Jul 08)
- RE: How big is the danger of IE? Yaakov Yehudi (Jul 08)
- RE: How big is the danger of IE? Sapheriel (Jul 08)
- RE: How big is the danger of IE? Eric Paynter (Jul 08)
- RE: How big is the danger of IE? Sapheriel (Jul 08)
- Re: How big is the danger of IE? nicolas vigier (Jul 08)
- RE: How big is the danger of IE? Larry Seltzer (Jul 08)
- RE: How big is the danger of IE? Eric Paynter (Jul 08)
- RE: How big is the danger of IE? Nick FitzGerald (Jul 08)
- RE: How big is the danger of IE? Larry Seltzer (Jul 08)
- Message not available
- RE: How big is the danger of IE? Nick FitzGerald (Jul 08)
- RE: How big is the danger of IE? Curt Purdy (Jul 11)
- RE: How big is the danger of IE? Eric Paynter (Jul 08)
- RE: How big is the danger of IE? Eric Paynter (Jul 08)
- RE: How big is the danger of IE? joe (Jul 08)
- RE: How big is the danger of IE? Eric Paynter (Jul 08)
- Re: How big is the danger of IE? Valdis . Kletnieks (Jul 09)
- <Possible follow-ups>
- RE: How big is the danger of IE? Randal, Phil (Jul 08)
- RE: How big is the danger of IE? Randal, Phil (Jul 08)
- RE: How big is the danger of IE? Skander Ben Mansour (Jul 08)