BetaONE will rise again!


Reply
  #1  
Old 13th Mar 08, 11:33 AM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,079
NewsBot will become famous soon enough
Two years after patch, a new IE5/6 FTP flaw
A flaw in the way Microsoft's Internet Explorer (IE) browser processes FTP commands could let attackers steal or erase data from a victim's FTP site.

The bug, which affects users of IE6 and the unsupported IE5 browser, gives an attacker a way of hijacking the victim's FTP sessions. But a successful attack would be very hard to pull off and would only work in very precise and targeted attacks, security experts said.

The attacker would need to know the victim's user name on the FTP server and the victim would have to already be logged into the server, using IE. Under those conditions, the victim could be sent a malicious FTP link that would then execute commands on the victim's FTP server.

This link could be sent to the browser via an invisible iFrame component, hidden on a malicious website, so the victim might not even know the attack was taking place. "It's something that people could use to steal data, but you'd have to know your target," said Derek Abdine, the principal software engineer with security vendor Rapid7, who unveiled the issue in a security advisory.

View: Full Article @ TechWorld

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
World of Warcraft Patch 2.3 going live today! NewsBot NeoWin News 0 13th Nov 07 02:28 PM
AMD developing patch for ATI security flaw NewsBot DriverHeaven News 0 13th Aug 07 10:00 PM
With Black Hat approaching, Apple in a rush to patch? NewsBot NeoWin News 0 27th Jul 07 12:37 PM
Unofficial IE patch saves humanity Alpine BetaONE News 0 25th Sep 06 01:22 PM
UNIX Authors Rush to Patch Telnet Flaw NewsBot NeoWin News 0 31st Mar 05 11:30 PM


All times are GMT +1. The time now is 10:28 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.