lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20070712181418.9382.qmail@securityfocus.com> Date: 12 Jul 2007 18:14:18 -0000 From: urtrapped9@...il.com To: bugtraq@...urityfocus.com Subject: Bogus BID 24744 After seeing all the references and digging myself i have come to a conclusion that this bid is a mistake. 1) Internet explorer does not allow any range or format or characters to be put in the address for a zone it has a proper format. 2) The zones classify and not load or whatever is written in the advisory. 3) The attacker can never know the zone settings and he cannot manipulate them in anyway. Can't see how the secniche claims attacker can modify registry through a web page. I would request the BID maintainers to take a closer look into this.