Most Popular Stories
- Samsung unveils long-awaited Galaxy Tab Internet tablet
- Google Chrome 7 will come with GPU acceleration
- Apple refreshes iPod Touch, adds dual camera
- Motorola warns against downloading unofficial Android 2.2 upgrade for Droid X
- Surprising lessons from a Florida college's iPad deployment
- Samsung unveils teaser of Galaxy Tab tablet
Events
- SharePoint Technology Conference
October 20 - 22 — Boston, MA - Register for The Security Standard 2010
September 13 - 14 — New York, NY - Northwestern University Master of Science in Information Systems (MSIS)
- Register for IT Roadmap Dallas 2010
September 14 — Dallas Convention Center
Sponsored Links
HOT TOPICS >> Q2 Earnings Roundup | Cloud Computing | Tablets | Security Vulnerabilities and Exploits
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Durable Smart Devices for Mobile Field Forces: Selection and Evaluation Criteria
- The Shortcut Guide to Secure, Managed File Transfer
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
- Cloud Computing: How To Make Your Own Silver Lining
- Reporting 2.0 – The next evolutionary step in web based business reporting
We never sell or give away your contact information. Our reader's trust comes first.
IE flaw allows any file on victim's PC to be read
Security consultant Jorge Luis Alvarez Medina conducted a live demonstration that saw him exploiting (yet another) flaw in Microsoft's Internet Explorer web browser. In this instance, Medina was able to read files on the victim's local drive with impunity. And not only is the flaw said to extend across all versions of Internet Explorer, it is also "not subject to a patching fix."
In a Computerworld article, Medina said that "it doesn't appear that the IE flaw is subject to patching because it encompasses design features related to how IE and Windows Explorer handle zone elevation, HTML code and MIME types."
Workarounds involved a list of configurations such as setting "IE Network Protocol Lockdown" mode, adjusting the security on Intranet Zones to "high" and disabling Active Scripting. Honestly, I'll just as soon recommend that users switch from Internet Explorer to something with less pervasive security problems. Do you agree?
For more on this story:
- check out this article at Computerworld
Related Articles:
Chrome 4 opens the door to third-party extensions
Microsoft issues emergency patch for Internet Explorer
Firefox 3.7 should see vast speed improvements
Google Chrome is now No. 3 browser
Microsoft confirms new Internet Explorer vulnerability
Related Stories
- Lead on other browsers narrows for Internet Explorer
- Founder of Netscape to make new browser
- Firefox architect not in favor of being bundled with Windows
- Google Chrome releases 1.0; no longer in beta
- Improving security on the cheap
- Google releases Chrome 6 on second anniversary of browser
- Chrome 6 enters beta, packs enhanced sync capabilities
- Hotmail upgrade not smooth sailing for all
- Internet Explorer gains ground on the browser front
- Security vulnerabilities continue to inundate software vendors
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |







