lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
From: larry at larryseltzer.com (Larry Seltzer) Subject: Re: shell:windows >>>>>Also, when the shell:windows reference is input into IE's address >>>>>bar field, it executes the code without a a dialogue box... >>>>> >>>Gimme a break. This is not a meaningful problem. >>It's as meaningful as the Mozilla issue. If your point is that that wasn't a meaningful problem either, then we can agree to disagree on the scope. I'll agree that getting this issue to run code of the choosing of the attacker is more difficult than some other unpatched IE holes, but it is not impossible. I disagree completely. The Mozilla problem, which I'll readily agree is not in the same league with most of the recent IE problems, allowed a local program to execute simply by visiting a web page that had the appropriate shell: link in a META tag. You actually think this is on the same level as requiring a user to type "shell:windows\system32\foo.exe" into the Address bar? Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blog.ziffdavis.com/seltzer larryseltzer@...fdavis.com
Powered by blists - more mailing lists