SLCentral - Your logical choice for computing and technology
Latest Deals   
Navigation
  • Home
  • Search
  • Forums
  • Hardware
  • Games
  • Tech News
  • Deals
  • Prices
  • A Guru's World
  • CPU/Memory Watch
  • Site Info
  • SL Newsletter
    Recieve bi-weekly updates on news, new articles, and more


    Forum home My SLBoards (Control Panel)View the calendar View the members list Read the FAQ Search the forums

    Go Back   SLCentral Forum > Feedback > SLNews
    User Name
    Password


    Reply
     
    Thread Tools Display Modes
      #1  
    Old 04-16-02, 08:56 PM
    Cutriss's Avatar
    Cutriss Cutriss is offline
    Dancing Hero
     
    Join Date: Feb 2001
    Location: Over there
    Posts: 1,163
    Cutriss is off the scale
    Default Don't touch that Back button...

    New bug identified in Internet Explorer that's as easy to trigger as it is to leave the page that triggers it.

    Seen on Slashdot, a posting on BugTraq is pointing out a huge gaping flaw in Internet Explorer. Simply put, a clever website developer can insert ********** that won't execute until you hit the Back button, and when you do, it executes that code in the security setting of the last viewed URL. This means that if you were to click a link from a trusted website that either got hijacked to a different website, or was maliciously programmed, you could hit the Back button to leave the site and the ********** would be able to execute arbitrary code on your local machine.

    The posting can be viewed on the SecurityFocus site, but since it's Slashdotted, you might want to wait a bit. I'd post the code here, but the vBulletin code won't let me use <XMP> or <CODE> properly.

    The provided code can execute Minesweeper, or execute an arbitrary application or command string on the browsing computer.

    It isn't yet known how widespread this bug exists in Internet Explorer, but I've verified it to work in my Windows XP build of IE, Build 6.0.2600.0000.xpclnt_qfe.010827-1803. Slashdot user ekrout has set up a demonstrating webpage to show the vulnerability in action, and allow you to test it.
    __________________
    "And knowing is half the battle!"
    Reply With Quote
      #2  
    Old 04-18-02, 05:46 AM
    amistadcliffman's Avatar
    amistadcliffman amistadcliffman is offline
    Forgot Plan
     
    Join Date: Apr 2001
    Location: Alien Terrarium
    Posts: 356
    amistadcliffman is off the scale
    Send a message via ICQ to amistadcliffman Send a message via AIM to amistadcliffman Send a message via Yahoo to amistadcliffman
    Default

    Hm, well it doesn't seem to affect netscape 6.2.

    Sounds cool though. I think I will put it on my website.
    __________________
    Road Runner!!!!
    Reply With Quote
      #3  
    Old 04-18-02, 07:34 AM
    Cutriss's Avatar
    Cutriss Cutriss is offline
    Dancing Hero
     
    Join Date: Feb 2001
    Location: Over there
    Posts: 1,163
    Cutriss is off the scale
    Default

    Quote:
    Originally posted by amistadcliffman
    Hm, well it doesn't seem to affect netscape 6.2.

    Sounds cool though. I think I will put it on my website.
    No, it only affects Internet Explorer. Some Netscape versions (Early 4.x) do crash when encountering the code though, presumably because they have better system protections on what Java can and can't do.
    __________________
    "And knowing is half the battle!"
    Reply With Quote
    Reply


    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    vB code is On
    Smilies are On
    [IMG] code is On
    HTML code is On
    Forum Jump



    All times are GMT -8. The time now is 01:14 AM.

    Archive - Search Engine Friendly URLs by vBSEO 3.0.0 RC6 © 2006, Crawlability, Inc. Top
    Browse the various sections of the site
    Hardware
    Reviews, Articles, News, All Reviews...
    Gaming
    Reviews, Articles, News...
    Regular Sections
    A Guru's World, CPU/Memory Watch, SLDeals...
    SLBoards
    Forums, Register(Free), Todays Discussions...
    Site Info
    Search, About Us, Advertise...
    Search Engine Friendly URLs by vBSEO 3.0.0 RC6 © 2006, Crawlability, Inc. Legal | Advertising | Site Info