This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

"Month of Browser Bugs" released

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1459
Last Updated: 2006-07-03 14:12:10 UTC
"HD Moore published a blog entry on Sunday stating that he plans to issue a new browser bug each day through the month of July. Two are already out and it looks like one of them is pretty nasty…"

- http://metasploit.blogspot.com/2006/07/mon…owser-bugs.html
July 02, 2006
"…I will publish one new vulnerability each day during the month of July as part of the Month of Browser Bugs project…" - HD Moore


:( :wtf:
It appears these advisories (one a day) will go on for a month. I will NOT be posting anymore of HD Moore's findings. 'Done here as an example of what you'll be seeing all month long from Secunia:

- http://secunia.com/advisories/20906/
Release Date: 2006-07-04
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 6.x
…The vulnerability has been confirmed on a fully patched system running Windows XP SP2 with Internet Explorer 6.0. Other versions may also be affected.
Solution:
Disable the "Run ActiveX controls and plug-ins" setting for all but trusted sites.
Provided and/or discovered by:
HD Moore…

:(