IE5 - same vulnerabilities, only some fixed

From: Most Psychoid (psychoidat_private)
Date: Fri Mar 19 1999 - 02:46:01 PST

  • Next message: Patrick Oonk: "Promail trojan"

    Hello,
    
    The new Microsoft Internet Explorer 5 (I checked Version: 5.00.0910.1309)
    still allows Frame Spoofing and reading of local Files as described by
    Georgi Guninski (see http://www.whitehats.com/guninski/read.html).
    
    Another new feature named "AutoComplete" stores entries (which also may be
    passwords). Just another new source for passwords which had not been saved
    in IE 4.x.
    
    The Crash-bugs seem to be removed. I could not crash my default installed
    IE 5 using the known exploits.
    
    So far,
    
    psychoid
    
    ---
    Sent through Global Message Exchange - http://www.gmx.net
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:39:17 PDT