<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; IE-vulnerability</title>
	<atom:link href="http://www.darknet.org.uk/tag/ie-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Internet Explorer Zero-Day Accidentally Leaked To Chinese Hackers</title>
		<link>http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/</link>
		<comments>http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/#comments</comments>
		<pubDate>Tue, 04 Jan 2011 11:02:38 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[breakaaspecial]]></category>
		<category><![CDATA[breakcircularmemoryreferences]]></category>
		<category><![CDATA[cross_fuzz]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[ie 0day]]></category>
		<category><![CDATA[ie zero day]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[IE-vulnerability]]></category>
		<category><![CDATA[internet explorer 0day]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[lcamtuf]]></category>
		<category><![CDATA[michal-zalewski]]></category>
		<category><![CDATA[zalewski]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3025</guid>
		<description><![CDATA[First up, happy new year &#8211; let&#8217;s hope 2011 is an interesting year for the infosec community. Anyway today&#8217;s story is about the recently released tool cross_fuzz by Michal Zalewski and an inadvertent leak that have occurred. tl;dr version is something like this: Michal Zalewski writes a DOM fuzzer, fuzzes IE, finds flaws, Chinese dudes [...]]]></description>
			<content:encoded><![CDATA[<p>First up, happy new year &#8211; let&#8217;s hope 2011 is an interesting year for the infosec community. Anyway today&#8217;s story is about the recently released tool <a href="http://www.darknet.org.uk/2011/01/cross_fuzz-a-cross-document-dom-binding-fuzzer/">cross_fuzz</a> by Michal Zalewski and an inadvertent leak that have occurred.</p>
<p>tl;dr version is something like this: Michal Zalewski writes a <a href="http://www.darknet.org.uk/2011/01/cross_fuzz-a-cross-document-dom-binding-fuzzer/">DOM fuzze</a>r, fuzzes IE, finds flaws, Chinese dudes Google some .dll functions and find fuzzer results.</p>
<p>It could be some kind of weird coincidence, or you could read a whole conspiracy theory into it (unreleased tool, very specific search terms etc.).</p>
<blockquote><p>Details concerning a potentially serious security vulnerability in fully patched versions of Microsoft&#8217;s Internet Explorer have been leaked to people in China, a researcher warned over the weekend.</p>
<p>Michal Zalewski, a security researcher at Google, blogged that data concerning at least one “clearly exploitable crash” in the Microsoft browser was inadvertently disclosed to people who were using a Chinese IP address. Details about the bug, which resides in the mshtml.dll component, were stored on a server that had accidentally been indexed by Google, Zalewski wrote elsewhere. On December 30, detailed search queries showed that the sensitive information, in addition to files for an unpublished security tool, had been retrieved by the unknown party.</p>
<p>“This pattern is very strongly indicative of an independent discovery of the same fault condition in MSIE by unrelated means,” Zalewski wrote. “Other explanations for this pair of consecutive searches seem extremely unlikely.”</p>
<p>The bug leads to arbitrary crashes in the EIP, or extended instruction pointer, of machines running the Microsoft browser. Zalewski said the flaw “is pretty much fully attacker-controlled.” It was uncovered using cross_fuzz, a security tool the researcher developed in his spare time more than two years ago to identify potential security vulnerabilities in IE, Firefox, and other browsers. Since its release, the tool has helped to identify nearly 100 various browser bugs.</p></blockquote>
<p>You can find the complete history between MZ and <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> regarding both ref_fuzz and cross_fuzz here:</p>
<p><a href="http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt">fuzzer_timeline.txt</a></p>
<p>As for the &#8216;discovery&#8217; it does seem likely that someone else had already discovered the same vulnerability and were searching for further information about it and if it had been published/disclosed. The search logs are here:</p>
<p><a href="http://lcamtuf.coredump.cx/cross_fuzz/known_vuln.txt">known_vuln.txt</a></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>A statement attributed to Jerry Bryant, group manager in Microsoft&#8217;s Response Communications, said company researchers are working to reproduce the crash to see if the underlying vulnerability can be exploited by malicious hackers.</p>
<p>“At this point, we&#8217;re not aware of any exploits or attacks for the reported issue and are continuing to investigate and monitor the threat environment for any changes,” Bryant said.</p>
<p>Zalewski provided this account of his communications with Microsoft, which started in May 2008. In it, he claims that on December 21, Microsoft researcher David Ross “confirms being able to reproduce crashes locally right away.”</p>
<p>Zalewski said that Microsoft researchers asked him to delay the release of cross_fuzz until they had more time to investigate the crashes. He published his warning on New Year&#8217;s Day, after he learned that the crash logs and related files had been downloaded.</p>
<p>“These search queries are looking for information on two MSHTML.DLL functions – BreakAASpecial and BreakCircularMemoryReferences – that are unique to the stack signature of this vulnerability, and had *absolutely* no other mentions on the internet at that time,” he said.</p></blockquote>
<p><a href="http://www.darknet.org.uk/2011/01/cross_fuzz-a-cross-document-dom-binding-fuzzer/">cross_fuzz</a> has been released officially now by Zalewski after <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> have had some time to investigate the crashes further. The moral of the story is, once again don&#8217;t use Internet Explorer!</p>
<p>As right now, there is a potentially dangerous 0-day for IE in the wild and as we well known with <a href="http://www.darknet.org.uk/tag/patch-tuesday/">Patch Tuesday</a> it&#8217;ll be quite some time before it gets fixed.</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/01/03/ie_0day_leaked/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Internet+Explorer+Zero-Day+Accidentally+Leaked+To+Chinese+Hackers+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3025+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/&amp;t=Internet+Explorer+Zero-Day+Accidentally+Leaked+To+Chinese+Hackers" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/&amp;title=Internet+Explorer+Zero-Day+Accidentally+Leaked+To+Chinese+Hackers" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/&amp;title=Internet+Explorer+Zero-Day+Accidentally+Leaked+To+Chinese+Hackers" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/&amp;title=Internet+Explorer+Zero-Day+Accidentally+Leaked+To+Chinese+Hackers" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/&amp;title=Internet+Explorer+Zero-Day+Accidentally+Leaked+To+Chinese+Hackers" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F01%2Finternet-explorer-zero-day-accidentally-leaked-to-chinese-hackers%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/01/internet-explorer-zero-day-accidentally-leaked-to-chinese-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Releases Out-Of-Band Patch For IE 0-Day Vulnerability</title>
		<link>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/</link>
		<comments>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 08:01:14 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[crc-16]]></category>
		<category><![CDATA[data execution prevention]]></category>
		<category><![CDATA[dep]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacking-IE]]></category>
		<category><![CDATA[ie 0day]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[IE-security]]></category>
		<category><![CDATA[IE-vulnerability]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet explorere 0day]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patch tuesday]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[oob patch]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2457</guid>
		<description><![CDATA[Ah Microsoft is treating this one seriously after France and Germany advised users to avoid IE. The current strain being exploited only targets IE6 users, but one security company has developed an exploit for IE8 which also bypasses DEP (Data Execution Prevention). It was rumoured this was the exploit used last week to compromise Google [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> is treating this one seriously after <a href="http://www.eweek.com/c/a/Security/France-Germany-Say-Avoid-IE-Until-Security-Vulnerability-Patched-321481/">France and Germany advised users to avoid IE</a>.</p>
<p>The current strain being exploited only targets IE6 users, but one security company has developed an exploit for IE8 which also bypasses DEP (Data Execution Prevention).</p>
<p>It was rumoured this was the exploit used last week to compromise Google and various other high profile networks. Although I am skeptical as to why anyone was using IE inside Google? Perhaps doing cross browser testing for development, who knows.</p>
<blockquote><p>Microsoft will release an out-of-band patch Jan. 21 to fix the Internet Explorer vulnerability at the center of recent attacks on Google and other enterprises.</p>
<p>According to Microsoft, the patch is slated to be ready around 1 p.m. EST. If all goes according to plan, the patch will close a hole that has prompted France and Germany to advise users to avoid IE and the U.S. State Department to demand answers from China. Attackers have used the vulnerability to hit IE 6. Microsoft so far has said it has only seen limited, targeted attacks using the vulnerability.</p>
<p>Meanwhile, security researchers have continued to uncover information about the origin of the attack. Joe Stewart, director of malware research for SecureWorks&#8217; Counter Threat Unit, said his analysis of the code for the main Trojan involved in the attacks shows a more direct link to China. </p></blockquote>
<p>It&#8217;s very rare for them to push an <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-band patch</a> for anything but I guess there are still a LOT of IE users out there and this is a serious flaw.</p>
<p>It does seem to originate from China with the only discussions about the technical parts of the flaw and implementation being discussed on Chinese language sites.</p>
<p>As can be seen by a Google search here (<a href="http://www.google.com/search?q="crc_ta[16]"&#038;ie=utf-8&#038;oe=utf-8&#038;aq=t&#038;rls=org.mozilla:en-US:official&#038;client=firefox-a">&#8220;crc_ta[16]&#8220;</a>), after the first few English news sites reporting the flaw the rest of the results are in Chinese.</p>
<blockquote><p>According to Stewart, the code includes a CRC (cyclic redundancy check) algorithm implementation released as part of a Chinese-language paper on optimizing CRC algorithms for use in microcontrollers.</p>
<p>&#8220;This CRC -16 implementation seems to be virtually unknown outside of China, as shown by a Google search for one of the key variables, &#8216;crc_ta[16],&#8217;&#8221; Stewart noted in a SecureWorks blog post Jan. 20. &#8220;At the time of this writing, almost every page with meaningful content concerning the algorithm is Chinese.&#8221;</p>
<p>Up until this finding, Stewart told eWEEK, the factors leading people to point to China were patterns similar to previous Chinese malware.</p>
<p>&#8220;Unfortunately, when investigating malware, nothing is conclusive because digital evidence can be forged,&#8221; he said. &#8220;However, I believe the use of the Chinese algorithm certainly gives more credence to the attack code being Chinese in origin.&#8221;</p></blockquote>
<p>They really have no choice but to release this patch when faced with government pressure, you should see it hitting your Windows Update sometime today (Jan 21st).</p>
<p>Let&#8217;s hope this patch has been tested properly and doesn&#8217;t subject users to another <a href="http://www.darknet.org.uk/2009/12/microsoft-leaves-users-waiting-for-black-screen-of-death-fix/">black screen of death</a>.</p>
<p>It&#8217;s good to see some proactive initiatives by Microsoft, I hope they continue through 2010.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Microsoft-IE-Patch-for-ZeroDay-Vulnerability-Coming-Tomorrow-804909/">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2457+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;t=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F01%2Fmicrosoft-releases-out-of-band-patch-for-ie-0-day-vulnerability%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Zalewski (lcamtuf) Strikes Again &#8211; More Vulnerabilites in IE and Firefox</title>
		<link>http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/</link>
		<comments>http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/#comments</comments>
		<pubDate>Wed, 06 Jun 2007 05:12:51 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[firefox-vulnerability]]></category>
		<category><![CDATA[hacking-firefox]]></category>
		<category><![CDATA[hacking-IE]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-vulnerability]]></category>
		<category><![CDATA[internet-exploder]]></category>
		<category><![CDATA[internet-explorer]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/</guid>
		<description><![CDATA[Our Polish friend and expert security researcher, Michal Zalewski (lcamtuf), known for his endless stream of vulnerabilities in all manners of software, has struck again. This time with some pretty serious flaws in both Internet Exploder Explorer and Firefox. This time it&#8217;s 4, 2 in IE and 2 in Firefox. The first which effects fully [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Our Polish friend and expert security researcher, Michal Zalewski (lcamtuf), known for his endless stream of vulnerabilities in all manners of software, has struck again.</p>
<p>This time with some pretty serious flaws in both Internet <del datetime="2007-06-06T05:03:42+00:00">Exploder</del> Explorer and Firefox. This time it&#8217;s 4, 2 in IE and 2 in Firefox.</p>
<p>The first which effects fully patched IE6 and IE7 is pretty serious and can result in cookie theft,  cooking setting, page hijacking or memory corruption.</p>
<p>It&#8217;s based on a page update Race Condition (aka bait and switch vuln).</p>
<blockquote><p>When Javascript code instructs MSIE6/7 to navigate away from a page that meets same-domain origin policy (and hence can be scriptually accessed and modified by the attacker) to an unrelated third-party site, there is a window of opportunity for concurrently executed Javascript to perform actions with the permissions for the old page, but actual content for the newly loaded page</p></blockquote>
<p>The demo can be found here:</p>
<p><a href="http://lcamtuf.coredump.cx/ierace/">http://lcamtuf.coredump.cx/ierace/</a></p>
<p>The more serious of the two Firefox flaws is marked MAJOR and not CRITICAL and deals with the way the browser handles IFRAMEs (Cross-site IFRAME hijacking)</p>
<blockquote><p>Javascript can be used to inject malicious code, including key-snooping event handlers, on pages that rely on IFRAMEs to display contents or store state data / communicate with the server.</p></blockquote>
<p>A demo can be found here:</p>
<p><a href="http://lcamtuf.coredump.cx/ifsnatch/">http://lcamtuf.coredump.cx/ifsnatch/</a></p>
<p>The full e-mail with details of his vulnerabilities can be found here:</p>
<p><a href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063712.html">[Full-disclosure] Assorted browser vulnerabilities</a></p>
<p></p>
<p>You can also read more at <a href="http://www.theregister.co.uk/2007/06/05/browser_vulns_identified/">The Register</a> or <a href="http://www.eweek.com/article2/0,1759,2141952,00.asp">eWeek</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D594+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;t=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F06%2Fzalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

