funsec mailing list archives

RE: Secunia Reports Another IE7 Flaw


From: "Fergie" <fergdawg () netzero net>
Date: Wed, 25 Oct 2006 18:36:21 GMT

That's probably why it's rated "less critical". :-)

- ferg


-- Larry Seltzer <Larry () larryseltzer com> wrote:

The Secunia demo didn't really work for me.  I've configured IE7 to
generate pop-ups as new tabs and the address bar has different
dimensions than their demo is expecting. 

Of course that's not the default. I tried it and the exploit seems to
depend on the exact layout of the window, and the "fake" address was
scrolled off some to the left. It's something, but not much.

Larry Seltzer


--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: