Most Popular Stories
- Nearly half of U.S. businesses to have mobile apps this year
- Apple's iPad 3 will be unveiled first week of March, says report
- Why people don't really plan website migrations
- Chrome 17's new features enhance speed, security
- There's no escaping the app economy
- Infragistics buys SharePoint mobile tool company
Events
- CIO Summit
March 18- 21 — Miami, FL - Northwestern University Master's in Information Systems
- MDSL Telecom Expense Management Roadshow
Feb 21–23, 2012 — New York, Houston, Chicago - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Reporting 2.0 – The next evolutionary step in web based business reporting
- Cloud Computing: How To Make Your Own Silver Lining
- Results of a Survey on DevOpsTrends
- The Shortcut Guide to Secure, Managed File Transfer
- Demystifying The Android Malware
Firefox 2/IE 7 animated cursor exploit on the way
In a column for ZDnet, George Ou reveals that security firm Determina plans to release a proof of concept animated cursor exploit that will allow attackers to hijack Mozilla 2 and IE7 running on Vista. An attack could allegedly be stopped by Microsoft's DEP (Data Execution Prevention) in Windows XP SP2 and Vista but is confoundingly turned off by default in most Windows programs. Interestingly enough, IE7 has the advantage here, as Ou writes, "What's interesting about this is the fact that Firefox doesn't have the benefit of Protected Mode under Vista, which can somewhat mitigate the damage that can be done if Internet Explorer 7 is exploited by this vulnerability." Determina is waiting for Mozilla to issue a patch before releasing the exploit code. As you will recall, Microsoft will be releasing a patch for the vulnerability today.
For more on the attack:
- see this ZDnet column
Related Stories
- Hackers exploiting unpatched Windows DNS bug
- Mozilla to issue workaround for .ANI bug
- Microsoft addresses many bugs in this month's Patch Tuesday
- Windows flaw gets critical, patch coming tomorrow
- Zero-day Windows bug effects Vista, XP, Windows 2K
- New version of Firefox patches FTP flaw
- Symantec: Vista vulnerable to legacy exploits
- New Microsoft Word zero-day attack on the loose
- Zero-day bugs remain after Microsoft Patch Tuesday
- Patch Tuesday: Two's company
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




