Results 1 to 10 of 10

Thread: Nasty Data-Stealing Bug Haunts Internet Explorer 8

  1. #1
    I am Xtreme
    Join Date
    Oct 2004
    Location
    U.S.A.
    Posts
    4,743

    Nasty Data-Stealing Bug Haunts Internet Explorer 8

    This bug is from December for crying out loud! All off the other browsers even Safari has it fixed!! I'm actually happy there's a lot of browsers out there now a days. The Less sites only think about using IE the better off we are, but then again IE users keep us geeks in business


    original information on it.
    http://scarybeastsecurity.blogspot.c...ss-domain.html

    page from today:



    It works by abusing the standards relating to the loading of CSS style sheets. Approximately, the standards are:


    Send cookies on any load of CSS, including cross-domain.

    When parsing the returned CSS, ignore any amount of crap leading up to a valid CSS descriptor


    The defense calls for browsers to enforce the content-type checking for style sheets that are loaded from other sites. The authors stipulate that strict enforcement of this policy can break a very small number of sites, so a less-strict version also is detailed in the paper.

    The defense has been adopted in one for or another by Google Chrome, Mozilla Firefox, Apple Safari and Opera.


    Asus Z9PE-D8 WS with 64GB of registered ECC ram.|Dell 30" LCD 3008wfp:7970 video card

    LSI series raid controller
    SSDs: Crucial C300 256GB
    Standard drives: Seagate ST32000641AS & WD 1TB black
    OSes: Linux and Windows x64

  2. #2
    Xtreme Monster
    Join Date
    May 2006
    Location
    United Kingdom
    Posts
    2,182
    Does anybody remember the last time Internet Explorer 8 had an update?

  3. #3
    Xtreme Enthusiast
    Join Date
    Feb 2009
    Posts
    800
    Nobody remembers, because nobody cares.



    Not by me

  4. #4
    Xtreme Addict Chrono Detector's Avatar
    Join Date
    May 2009
    Posts
    1,142
    I never trusted Internet Explorer since version 6, it was all about security flaws and vulnerability. And yeah, I only use Internet Explorer for downloading Mozilla Firefox like that chart says, so true.
    AMD Threadripper 12 core 1920x CPU OC at 4Ghz | ASUS ROG Zenith Extreme X399 motherboard | 32GB G.Skill Trident RGB 3200Mhz DDR4 RAM | Gigabyte 11GB GTX 1080 Ti Aorus Xtreme GPU | SilverStone Strider Platinum 1000W Power Supply | Crucial 1050GB MX300 SSD | 4TB Western Digital HDD | 60" Samsung JU7000 4K UHD TV at 3840x2160

  5. #5
    Xtreme Enthusiast
    Join Date
    Mar 2008
    Location
    Alberta Canada
    Posts
    631
    my home install for win7 doesnt have IE...removed it using the vista AIK + 7lite (i think thats what its called, not the same maker of nlite and vlite)
    Current System:
    eVGA 680i SLi "A2" P30 BIOS
    intel Core 2 Quad Q6600 (currently at stock)
    OCZ ReaperX 4GB DDR2 1000 (running at DDR2 800 Speeds with cas4)
    320GB Seagate 7200.10
    XFX 8800GT XXX 512MB (stock clocks)
    auzentech X-Fi Prelude
    PC Power and Cooling Silencer 750 Quad Copper
    Win XP Pro

  6. #6
    Xtreme Member
    Join Date
    Jun 2008
    Location
    Vilnius, Lithuania
    Posts
    130
    Quote Originally Posted by metroid View Post
    does anybody remember the last time internet explorer 8 had an update?
    2010-08-10

  7. #7
    Xtreme Member Gilhooley's Avatar
    Join Date
    Nov 2006
    Posts
    164
    Quote Originally Posted by Karolis View Post
    2010-08-10
    And it's a unified update - it replaces all previous patches:

    http://www.microsoft.com/technet/sec.../MS10-053.mspx
    Q9650@4000 - Apogee GTX, Gigabyte X48-DS5, 8GB Corsair Dominator XMS2-8500, GTX480 El cheapo Asetek block, Audiophile 192 + Adam-A7, Win7

  8. #8
    Xtreme Enthusiast
    Join Date
    Mar 2005
    Location
    North USA
    Posts
    670
    http://www.mozilla.org/security/know...firefox30.html

    Click through to the reported dates. The issue here is that people make a story where there is nothing per market standards because it's still en vogue to bash MSFT when you have nothing else to say.

    Please stop posting non-news in this section as an excuse to create some sort of flame thread.
    Asus P6T-DLX V2 1104 & i7 920 @ 4116 1.32v(Windows Reported) 1.3375v (BIOS Set) 196x20(1) HT OFF
    6GB OCZ Platinum DDR3 1600 3x2GB@ 7-7-7-24, 1.66v, 1568Mhz
    Sapphire 5870 @ 985/1245 1.2v
    X-Fi "Fatal1ty" & Klipsch ProMedia Ultra 5.1 Speaks/Beyerdynamic DT-880 Pro (2005 Model) and a mini3 amp
    WD 150GB Raptor (Games) & 2x WD 640GB (System)
    PC Power & Cooling 750w
    Homebrew watercooling on CPU and GPU
    and the best monitor ever made + a Samsung 226CW + Dell P2210 for eyefinity
    Windows 7 Utimate x64

  9. #9
    Xtreme Mentor
    Join Date
    Jan 2009
    Location
    Oslo - Norway
    Posts
    2,879
    These links contains details information about hacking the IE and stealing data from the browser. I thought "Discussion of Warez, crackz, and pirated copyrighted material is not permitted in this forum."

    ASUS P8P67 Deluxe (BIOS 1305)
    2600K @4.5GHz 1.27v , 1 hour Prime
    Silver Arrow , push/pull
    2x2GB Crucial 1066MHz CL7 ECC @1600MHz CL9 1.51v
    GTX560 GB OC @910/2400 0.987v
    Crucial C300 v006 64GB OS-disk + F3 1TB + 400MB RAMDisk
    CM Storm Scout + Corsair HX 1000W
    +
    EVGA SR-2 , A50
    2 x Xeon X5650 @3.86GHz(203x19) 1.20v
    Megahalem + Silver Arrow , push/pull
    3x2GB Corsair XMS3 1600 CL7 + 3x4GB G.SKILL Trident 1600 CL7 = 18GB @1624 7-8-7-20 1.65v
    XFX GTX 295 @650/1200/1402
    Crucial C300 v006 64GB OS-disk + F3 1TB + 2GB RAMDisk
    SilverStone Fortress FT01 + Corsair AX 1200W

  10. #10
    I am Xtreme
    Join Date
    Oct 2004
    Location
    U.S.A.
    Posts
    4,743
    Quote Originally Posted by Sam_oslo View Post
    These links contains details information about hacking the IE and stealing data from the browser. I thought "Discussion of Warez, crackz, and pirated copyrighted material is not permitted in this forum."
    How is making people aware of security flaws any way associated with that subject? When web browsers have security flaws the best way for them to be dealt with is for the flaws to be disclosed, so the threat can be handled. In this case it is for IE users to use a different web browser until that bug is fixed. It still amazes me how many users continue to use IE even after they've managed to pick up malware and or viruses. I find it odd that MS has not fixed it yet on something that is a threat to their user base. There are a lot websites out there that require IE just for the ActiveX controls yet to access remote terminals. I care about security and I'm sure others do.
    Last edited by safan80; 09-05-2010 at 01:46 PM.


    Asus Z9PE-D8 WS with 64GB of registered ECC ram.|Dell 30" LCD 3008wfp:7970 video card

    LSI series raid controller
    SSDs: Crucial C300 256GB
    Standard drives: Seagate ST32000641AS & WD 1TB black
    OSes: Linux and Windows x64

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •