Jump to content

IE7 - First Day


Zeus_Hunt

Recommended Posts

Microsoft has failed to respond in any manner to the security company Secunia, which claims that it has discovered a vulnerability in Internet Explorer 7 in the very same day the browser was launched. Well, it couldn't have been a smooth debut for IE7, as it certainly won't be a smooth ride, but this is a case of the proverbial starting on the wrong foot.

“The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site. Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected,” revealed Secunia.

Secunia is also making available a test accessible via this link.

For a failed test, Secunia displays the following message: “Your browser is vulnerable! The test retrieved content from news.google.com in the context of your browser. This actually means that if you were logged into your bank account, any web site you are visiting would be able to retrieve confidential data from your bank. This could also be used to retrieve personal settings entered on sites like eBay or Paypal.”

viewpo0.gif View: Original Article

Link to comment
Share on other sites


  • Replies 7
  • Views 5.2k
  • Created
  • Last Reply

Checked the link

I got this with IE6 ie6vulry4.jpg

But this made me smile oprea9vulyg9.jpg

Wonder which browser that would be :D

Link to comment
Share on other sites


I don't believe this just checked the link on IE 7 and guess what

same Image

And it says "Your browser is vulnerable! The test retrieved content from news.google.com in the context of your browser.

This actually means that if you were logged into your bank account, any web site you are visiting would be able to retrieve confidential data from your bank. This could also be used to retrieve personal settings entered on sites like eBay or Paypal."

I'm glad that I had downloaded FF2.0 RC3

s.jpg

Link to comment
Share on other sites


Now according to Christopher Budd (SECURITY PROGRAM MANAGER) in his Blog ....

These reports are technically inaccurate: the issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all. Rather, it is in a different Windows component, specifically a component in Outlook Express. While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express.
Link to comment
Share on other sites


ROMANTICGUY50
Now according to Christopher Budd (SECURITY PROGRAM MANAGER) in his Blog ....
These reports are technically inaccurate: the issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all. Rather, it is in a different Windows component, specifically a component in Outlook Express. While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express.

Yeah I tried it on IE and it came back like u all said. Glad I use FireFox

Link to comment
Share on other sites


i think it is an outlook express problem so get ALL the current updates if you use IE...or.... stick to firefox and opera

Link to comment
Share on other sites


  • 2 weeks later...
Guest Stormrage

Well i also think that the problem is in Outlook not IE7, because, i use a slipstreamed version of xp, and since i hate Outlook i removed Outlook Express from the setup disc with N-Lite.

My Internet Explorer 7 passes the test.

So, i reckon it isnt in the IE7, that the problem lies. It is just the crappy Outlook.

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...