Zeus_Hunt Posted October 20, 2006 Share Posted October 20, 2006 Microsoft has failed to respond in any manner to the security company Secunia, which claims that it has discovered a vulnerability in Internet Explorer 7 in the very same day the browser was launched. Well, it couldn't have been a smooth debut for IE7, as it certainly won't be a smooth ride, but this is a case of the proverbial starting on the wrong foot. “The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site. Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected,” revealed Secunia. Secunia is also making available a test accessible via this link.For a failed test, Secunia displays the following message: “Your browser is vulnerable! The test retrieved content from news.google.com in the context of your browser. This actually means that if you were logged into your bank account, any web site you are visiting would be able to retrieve confidential data from your bank. This could also be used to retrieve personal settings entered on sites like eBay or Paypal.” View: Original Article Link to comment Share on other sites More sharing options...
Zeus_Hunt Posted October 20, 2006 Author Share Posted October 20, 2006 Checked the linkI got this with IE6 But this made me smile Wonder which browser that would be :D Link to comment Share on other sites More sharing options...
ranji Posted October 20, 2006 Share Posted October 20, 2006 I don't believe this just checked the link on IE 7 and guess what same Image And it says "Your browser is vulnerable! The test retrieved content from news.google.com in the context of your browser.This actually means that if you were logged into your bank account, any web site you are visiting would be able to retrieve confidential data from your bank. This could also be used to retrieve personal settings entered on sites like eBay or Paypal."I'm glad that I had downloaded FF2.0 RC3 Link to comment Share on other sites More sharing options...
Zeus_Hunt Posted October 20, 2006 Author Share Posted October 20, 2006 Now according to Christopher Budd (SECURITY PROGRAM MANAGER) in his Blog ....These reports are technically inaccurate: the issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all. Rather, it is in a different Windows component, specifically a component in Outlook Express. While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express. Link to comment Share on other sites More sharing options...
ROMANTICGUY50 Posted October 20, 2006 Share Posted October 20, 2006 Now according to Christopher Budd (SECURITY PROGRAM MANAGER) in his Blog ....These reports are technically inaccurate: the issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all. Rather, it is in a different Windows component, specifically a component in Outlook Express. While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express. Yeah I tried it on IE and it came back like u all said. Glad I use FireFox Link to comment Share on other sites More sharing options...
dMog Posted October 20, 2006 Share Posted October 20, 2006 i think it is an outlook express problem so get ALL the current updates if you use IE...or.... stick to firefox and opera Link to comment Share on other sites More sharing options...
Guest WuDiLanJieLang Posted October 29, 2006 Share Posted October 29, 2006 totally agreed :o ie7 are crap :sneaky: Link to comment Share on other sites More sharing options...
Guest Stormrage Posted November 2, 2006 Share Posted November 2, 2006 Well i also think that the problem is in Outlook not IE7, because, i use a slipstreamed version of xp, and since i hate Outlook i removed Outlook Express from the setup disc with N-Lite.My Internet Explorer 7 passes the test.So, i reckon it isnt in the IE7, that the problem lies. It is just the crappy Outlook. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.