Who framed Internet Explorer
by Volker Weber
We discovered that it is possible for an attacker to execute script on any page that contains <frame> or <iframe> elements, ignoring any protocol or domain restriction set forth by Internet Explorer. This means that an attacker can steal cookies from almost any site, access and change content in sites and in most cases also read local files and execute arbitrary programs on the client's machine (script in the "My Computer" zone).
To give you a little demonstation what an iframe is, look at your files on my website. If this window is empty, you are not using Internet Explorer 5 (and "better"):
Comments
Daß mir mein Browser meine Daten anzeigt ist erstmal kein Problem für mich, insoweit ist dieses Script erstmal nichts wildes. Allerdings sollte man das die Option "Programme und Dateien in einem Iframe starten" tatsächlich deaktivieren, um einen blinden Scriptaufruf in den iframe hinein von der externen Domäne zu verhindern.
Jens
Post a comment
Recent comments
Gregory Engels
on International OpenOffice market shares at 16:53
Mathias Ziolo
on International OpenOffice market shares at 14:58
Gregory Engels
on International OpenOffice market shares at 14:47
Gregory Engels
on International OpenOffice market shares at 14:17
Andrew Magerman
on International OpenOffice market shares at 11:19
Hans Bornich
on Download and install Symphony 3 Beta 2 in 20 easy to follow steps at 10:35
Hynek Kobelka
on Leiterin Kommunikation und Presse, ahnungslos at 10:02
Dirk Steins
on Do you see it? at 08:01
Arthur Fontaine
on Do you see it? at 07:43
patrick picard
on Do you see it? at 00:30
Mathias Ziolo
on Leiterin Kommunikation und Presse, ahnungslos at 18:21
Thomas Lang
on FT.com - A fight over freedom at Apple's core at 17:35
Giulio Campobassi
on Download and install Symphony 3 Beta 2 in 20 easy to follow steps at 11:23
Peter Foster
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 19:17
Volker Weber
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 07:38
Peter Foster
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 03:18
Paul Mooney
on FT.com - A fight over freedom at Apple's core at 18:12
Todd dal
on iPhone OS 3.1.3 brings back Internet Tethering to unlocked iPhones at 23:03
Frank Paolino
on Clothing drive at 22:47
Craig Wiseman
on Embrace Life at 22:27
Volker Weber
on Clothing drive at 20:40
Carl Tyler
on Clothing drive at 20:28
Claude Lehmann
on FT.com - A fight over freedom at Apple's core at 19:13
Ragnar Schierholz
on FT.com - A fight over freedom at Apple's core at 19:02
Volker Weber
on FT.com - A fight over freedom at Apple's core at 12:23



