RSSMicro.com Search - RSS Feed Search Engine - RSS Feed Directory
Dedicated RSS Feed Search Engine
 Search 3.2 million RSS feeds
The most comprehensive RSS feed search on the web
Top Stories  |  FeedRank Checker

Published

   Last Hour

   Last Day

   Past Week

   Past Month

 Anytime







Featured
RSS Feeds


CNN RSS Feeds

Reuters RSS Feeds

MSNBC RSS Feeds

New York Times RSS Feeds

Washington Post RSS Feeds

CNBC RSS Feeds

ABC News RSS Feeds

Fox News RSS Feeds

Sky News RSS Feeds

Forbes RSS Feeds

CNET RSS Feeds

Unicef RSS Feeds

PBS RSS Feeds

Wall Street Journal RSS Feeds

Financial Times RSS Feeds

Business Week RSS Feeds

Bloomberg RSS Feeds

TheStreet RSS Feeds

ESPN RSS Feeds

   


»Click here to calculate your site FeedRank Today«

FeedRank - RSSMicro Search

FeedRank, a newly developed algorithm for ranking RSS feeds only on RSSMicro
Click here to learn more


F-Secure Antivirus Research Weblog


FeedRank: 5/10  5/10  Good  ---  www.f-secure.com
Weblog of F-Secure Antivirus Research Team ...

 

 
Friday, June 27, 2008 --- 63 days ago
Microsoft's Internet Explorer 6 has a reported cross-domain scripting vulnerability which could potentially expose user credentials (such as usernames/passwords) and allow cookie hijack sessions. Based on the results of our most recent poll : …this won't directly affect 98% of our readership. But as Mike Clark commented , "I answered Firefox, but I filled out the survey in IE6! This is because I am at work and my boss specifically refuses to allow me to use FF". So at least one of you has to use IE 6. As per reports , the vulnerability exploits Internet Explorer 6 installed on Windows XP SP2/SP3. The latest version of Internet Explorer (IE 7) with its improved handling of JavaScript protocol URLs is not vulnerable. This vulnerability has been reported to Microsoft and the research team has created a proof of concept: http://raffon.net/research/ms/ie/crossdomain/string.html If you open the link in IE 6, you'll see that the domain raffon.net has been linked to the cookie of different domain, i.e. Google.com. It's a PoC and isn't yet known to be in the wild, but it is considered to be moderately critical as many people still use IE 6 . Vulnerability Team post by — Jay On 27/06/08 At 02:44 PM ...




Recent Posts





 Facebook     Del.icio.us     Digg     StumbleUpon     Reddit     Google
Copyright © 2008 RSSMicro.com