Oh look! A big hole in Mozilla
- STRESSTEST
- DBB DemiGod
- Posts: 6574
- Joined: Sun Nov 21, 1999 3:01 am
Oh look! A big hole in Mozilla
Time to get those patches boys *smirk*
http://news.com.com/Security+hole+found ... g=nefd.top
http://news.com.com/Security+hole+found ... g=nefd.top
- STRESSTEST
- DBB DemiGod
- Posts: 6574
- Joined: Sun Nov 21, 1999 3:01 am
actually I use Opera Another reason to smile
Honestly I don't pay much attention to IE flaw postings since I dont use the browser. But one thing I do rememeber about them is that they usually include a MS hotfix # which is easily downloaded at MS's site. That the link you are talking about? Having said that, your point seems groundless?
Honestly I don't pay much attention to IE flaw postings since I dont use the browser. But one thing I do rememeber about them is that they usually include a MS hotfix # which is easily downloaded at MS's site. That the link you are talking about? Having said that, your point seems groundless?
Which is still a day too late.Tetrad wrote:The "bug" existed for 2 years, but there hasn't been a workable exploit known until just recently. And the day that the exploit was found, a patch was released.DCrazy wrote:I just think it's funny that this bug has existed for 2 years
Zero day == bad
Zero day == SQL Slammer type worm
Zero day == -$$$
um no, not quite, DCrazy.
you might want to read the acutal bug report
its a discussion about whitelisting external protocols.
Also of note, its not fixed in IE either.
you might want to read the acutal bug report
its a discussion about whitelisting external protocols.
Also of note, its not fixed in IE either.
Well, check this one out, posted the same day as yours. Launching a vbscript: URL launched IE.
Either way, the solution is NOT to tell users to disable the feature altogether in about:config, but to tell them to be on the lookout and create an option in the Preferences menu about it. After all, disabling it outright would cause descent3:// links to not function. This is a feature of the Windows OS after all, and basically it boils down to "if a program has a flaw and registers itself as a protocol, it's possible to mess with that program by sending it a malformed URL".
Either way, the solution is NOT to tell users to disable the feature altogether in about:config, but to tell them to be on the lookout and create an option in the Preferences menu about it. After all, disabling it outright would cause descent3:// links to not function. This is a feature of the Windows OS after all, and basically it boils down to "if a program has a flaw and registers itself as a protocol, it's possible to mess with that program by sending it a malformed URL".
- STRESSTEST
- DBB DemiGod
- Posts: 6574
- Joined: Sun Nov 21, 1999 3:01 am
- BUBBALOU
- DBB Benefactor
- Posts: 4198
- Joined: Tue Aug 24, 1999 2:01 am
- Location: Dallas Texas USA
- Contact:
Or stop surfing Pr0n, Warez, Crackz, Serialz, Cheatz, Bit Torrent, just to name a few....~!woodchip wrote:If you're using IE you better find something else: "Some researchers had begun recommending that people worried about online security stop using the IE browser altogether."
Remember kiddies ITD's can be transmitted without using protection.
A. We're not talking about IE security, we're talking Mozilla. So the correct, on topic response would have been "If you're using Mozilla you better get patched."woodchip wrote:If you're using IE you better find something else:
"Some researchers had begun recommending that people worried about online security stop using the IE browser altogether."
B. Even if we were talking about IE, people hate it when you tell them what's better for them without any grounds. So, you may consider saying "If you're using IE, I cordially invite you try Mozilla."
C. Give it a rest. We're not boasting which browser has a bigger cock size, we're pointing out a flaw. In fact, here is a prime example of how all browsers are just as vulnerable as IE is. Two years a known flaw goes unfixed. Imagine the rants and raves if it was in IE. But no, it's Godlike Mozilla, the holy grail of Internet browsers, world peace, cold fusion and fat free twinkies would be possible if we all used Mozilla. In this case you may consider saying "".
This lesson in Internet etiquette brought to you by "Mom's Molten Boron".
Interesting links, the last one doesn't freeze my system like it says. However, how is that different than just using file:/// urls?fliptw wrote:Also of note, its not fixed in IE either.
file:// is handled internally by the browser.Topher wrote: Interesting links, the last one doesn't freeze my system like it says. However, how is that different than just using file:/// urls?
the basic issue is what to do about protocols that browser doesn't handle interally, either by default or thru a plugin, in windows(since you can register protocols with specific apps), most browsers till recently handed it off to the OS to deal with.
this particular thread started because of an exploit in a specific external protocol.
- Vindicator
- DBB Benefactor
- Posts: 3166
- Joined: Mon Dec 16, 2002 3:01 am
- Location: southern IL, USA
- Contact:
- Mr. Perfect
- DBB Fleet Admiral
- Posts: 2817
- Joined: Tue Apr 18, 2000 2:01 am
- Location: Cape May Court House, New Jersey.
- Contact:
- STRESSTEST
- DBB DemiGod
- Posts: 6574
- Joined: Sun Nov 21, 1999 3:01 am
Im not aware of it, but probably so. I wouldn't be supprised if that is true in the least. And I don't need proof, I'll take your word for it.Diedel wrote:Hadn't there been an Update to Opera just recently because of a security leak in it, Mr. Wiseguy Stresstest?
The whole tone in my type was a tongue-in-cheek shot at the elitist attitudes associated (in my oppinion only) with SOME mozilla users. And to point out that nothing is perfect in the software world.
Topher I believe has summed up things very well though. Couldn't have said it better myself.
Just an FYI also Diedel, I won't allow you to start a flame war in here either. Not an accusation, just info
- STRESSTEST
- DBB DemiGod
- Posts: 6574
- Joined: Sun Nov 21, 1999 3:01 am
- KompresZor
- DBB Captain
- Posts: 919
- Joined: Wed Jul 31, 2002 2:01 am
- Location: Clearfield, Pennslyvania