<http://www.theregister.co.uk/2010/10/01/microsoft_ie_twitter_rolling_attack/>
<quote>
An information disclosure threat in Microsoft's Internet Explorer
affects all supported versions of the browser and, among other things,
makes it trivial for attackers to force victims to post
attacker-dictated messages on Twitter, a security researcher said this
week.
The “Twitter-rolling” attack, which was first described last month, is
the result of the way the browser parses CSS, or cascading style
sheets, security researcher Chris Evans said. In an update posted on
Wednesday, he demonstrated just how easy it is to exploit the flaw and
said that “Microsoft have not stated when users of IE6, IE7, and IE8
will be afforded protection.”
</quote>
|
|
0
|
|
|
|
Reply
|
Hardon
|
10/2/2010 9:38:40 AM |
|