Southern writes:Jorge Luis Alvarez Medina, a security consultant working for Core Security, has discovered a string of vulnerabilities in Internet Explorer that make it possible for an attacker to gain access to your C drive - complete with files, authentication and HTTP cookies, session management data, etc.
Exploitation of the vulnerability relies solely on the ability for a would-be attacker to provide malicious HTML content from a website and to predict the full path name for the file that will be used to cache it locally on the victim's system," says the advisory Core Security published. "If the entire path name can be predicted, the attacker can cause a redirection to the locally stored file using an URI specified in UNC form and force the local content to be rendered as an HTML document, which will permit to run scripting commands and instantiate certain ActiveX controls."
net-security.org
IE vulnerability offers your files to hackers
Posted on Thursday, January 28, 2010 @ 15:02:33 CST in Security
|
Google Chrome Multiple Vulnerabilities
Posted on Tuesday, January 26, 2010 @ 21:55:06 CST in Security
|
Patch Tuesday heads-up: MS to fix *critical* IE, Office security holes
Posted on Monday, December 07, 2009 @ 14:40:35 CST in Security
|
PHP Multiple Vulnerabilities
Posted on Sunday, November 22, 2009 @ 12:44:17 CST in Security
|
Thousands of web sites compromised, redirect to scareware
Posted on Thursday, November 19, 2009 @ 12:48:04 CST in Security webservant writes:
|
Adobe Reader Multiple Vulnerabilities
Posted on Saturday, November 07, 2009 @ 23:52:17 CST in Security papamike writes:
|