Exploit allows malicious site to execute arbitrary code by showing user 404 and assuming they click "Back".
Sample exploit (executes minesweeper) :
http://www.babysimon.co.uk/iebug.html
As always, Mozilla is available from http://www.mozilla.org/
Sample exploit (executes minesweeper) :
http://www.babysimon.co.uk/iebug.html
As always, Mozilla is available from http://www.mozilla.org/
(no subject)
Date: 2002-04-17 02:33 am (UTC)Where did you hear about this one from?
If you're a Windows user, here's the direct link to the current latest Mozilla download; it's about 9 Mb.
http://download.mozilla.org/pub/mozilla/releases/mozilla0.9.9/mozilla-win32-0.9.9-installer.exe
(no subject)
Date: 2002-04-17 02:34 am (UTC)I may just not be understanding, but only the third link behaves as I'd expect from your post.
The first two give me a 404, but don't run minesweeper when I click back - I just get a blank window with gibberish in the Address box.
The fourth one shows me a Google search screen, and then when I click back, I get a dialog box with complete gibberish.
I'm confused.
(no subject)
Date: 2002-04-17 02:38 am (UTC)(no subject)
Date: 2002-04-17 02:41 am (UTC)via slashdot (I only read it for the headlines!)
(no subject)
Date: 2002-04-17 02:42 am (UTC)(no subject)
Date: 2002-04-17 03:18 am (UTC)(no subject)
Date: 2002-04-17 06:28 am (UTC)That's useful - despite being the version shipped with Win98SE, MS seem to have discontinued support for it, and I don't want to 'upgrade' to 5.5 or 6.0