Fundet i NANAE:
---- start ----
Another Big MS Browser Hole Found
By Michelle Delio
11:41 a.m. April 17, 2002 PDT
Internet Explorer users who click their browser's back button open
the Windows operating system to a malicious hack attack.
When users hit the back button on Explorer's toolbar, the browser's
security settings for the "Internet" zone can be bypassed, and the
browser
will automatically execute malicious code embedded into a site's URL.
The problem is caused by what can politely be described as a design
flaw
in Explorer. When a Web page fails to load, Explorer displays a
standard
error message. This message is set to operate in the "Local Computer
Zone"
security setting, which by default allows scripting to run
automatically.
Full story
http://wired.com/news/technology/0,1282,51899,00.html
---- slut ----
Umiddelbart ser det ud til at den er god nok, exploiten virker i hvert
fald på denne her maskine (selvom VShield godt nok finder "malicious
code" i temporary internet files).
--
Niels Callesøe - nørd light @work
http://www.pcpower.dk/disclaimer.php
pfy[at]nntp.dk
Jeg repræsenterer med denne udtalelse mig selv og ikke TDC Internet.