December 17, 2004

Secunia reports new IE vulnerability


by brian_turner

Secunia reports a new cross-site scripting vulnerability in Internet Explorer, that even people who downloaded the Windows XP Service Pack 2 update will be vulnerable to.

Using a live example, Secunia suggest that this could be very easily exploited in phishing, allowing phishers not simply to create spoofed websites URLs, but also fake SSL signatures and hijack cookies.

This comes as something of an embarrassment for microsoft, who had lauded the SP2 update as a major security milestone for the company.

In related news, Microsoft’s recent acquisition of Giant – an anti-spyware vendor – means that Microsoft will now be able to offer spyware checks for its customers. However, according to the report at Security Focus, Microsoft may charge extra for new security software:

Microsoft’s tool, expected to be available within 30 days, initially will be free but the company isn’t ruling out charging for future versions. “We’re going to be working through the issue of pricing and licensing,” said Mike Nash, vice president of Microsoft’s security business unit. “We’ll come up with a plan and roll that out.”

Questions? Discuss this in our Internet Business forums for help and advice

Story link: Secunia reports new IE vulnerability

Add to Bookmarks:

ADD TO DEL.ICIO.US     ADD TO DIGG     ADD TO FURL
ADD TO STUMBLEUPON     ADD TO YAHOO MYWEB     ADD TO GOOGLE     ADD TO SPURL

 

Leave a Reply




 

Previous: « Media Search: Blinkx TV & Yahoo! video
Next: Symantec’s $13 billion Veritas merger »

Visited 1827 times, 1 so far today