Bugtraq mailing list archives

RE: Serious security Flaw in Microsoft Internet Explorer - Zone Spoofing


From: "j jf" <jjfjjf69 () hotmail com>
Date: Sat, 13 Oct 2001 08:03:41 +0000

I found a way to overcome this hole for now:

Mark OFF all 3 options at the IE Local IntRAnet Security Zone
(Include all local intRAnet, sites, network path UNC).

Now press the advanced key and define your company DNS network zones,
You can use wild cards: *.mycompany.com

I haven’t tested it thoroughly, yet it seems to work and http://user%40NONdottedIP
Is accounted as internet rather than Local IntRAnet.

Regards,


_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp


Current thread: