Go Back   United Bimmer Community - BMW Forum > UnitedBimmer- Off Topic > United Off Topic  **FOR MEMBERS ONLY**
Register FAQ Members List Calendar Advertise With Us Mark Forums Read

Welcome to United Bimmer Community - BMW Forum .

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact
contact us
.

United Off Topic  **FOR MEMBERS ONLY** Chat about whatever! Off-topic chat forum. (Be sure to appropriately title posts that are NWS) You must be registred and logged in to see sub-forums

Reply
 
Thread Tools
Old 12-10-2005, 04:20 AM   #1
komodo
 
komodo's Avatar

Name: komodo
Title: Administrator
Status: Offline
Join Date: Apr 2005
Location: Athens, GA
Rate My Car: 71 / 337
Your Ride: 1995 M3
Microsoft Thanks Google for IE Patch

http://www.betanews.com/article/Micr...Fix/1134062428

Quote:

Google this week rolled out a fix to mitigate the risk from a newly discovered vulnerability in Internet Explorer that puts users of Google Desktop at risk even if they are running a fully updated system. Microsoft developers thanked Google for their work and say they are working on a patch for IE.

Uncovered by Israeli hacker Matan Gillon, the security hole involves a problem with the way IE imports cascading style sheets (CSS) from other Web sites, a technique referred to as cross site scripting (XSS). IE will import any type of file with a bracket, regardless of whether or not it's valid CSS.

By combining the flaw with Google's Desktop Search, a malicious Web site could read personal data off a visitor's machine.

"Our investigation indicates that this issue will have limited impact because an effective attack requires a website to expose sensitive information in a specific way. Basically, an attacker would need to find a way to make a response look like a Cascading Style Sheet, and that response would need to contain sensitive information," explained Microsoft security researcher Michael Howard.

Gillon supplied proof of concept code using Google News to highlight the potential risk. "A complete exploit can also iterate through the result pages to get more data and log the results on a remote server," he said. But Google has now closed that hole.

"Google has done a good thing for the protection of our mutual customers by mitigating the issue on their servers. We think that is great," added Howard.

"The underlying cross-site issue still exists within IE and I want to reassure you that we are investigating the root cause of this issue. Once the investigation is complete we'll take appropriate action for our customers which may include fixing this in a future security update for IE."
Oh the irony. haha
__________________

  Reply With Quote
Sponsored Links
Old 12-10-2005, 10:39 AM   #2
witeshark
 
witeshark's Avatar

Name: witeshark
Title: Suspended License
Status: Offline
Join Date: Apr 2005
Location: Miami FL
Rate My Car: 84 / 337
Your Ride: 89 325i 5 speed
Yup. Another such irony
  Reply With Quote
Old 12-10-2005, 12:48 PM   #3
bmwcrazy

Name: bmwcrazy
Title: Member
Status: Offline
Join Date: Oct 2005
User not setup in Rate My Car.
Click here to set it up.
Google can make a lot of money if they start to charge Microsoft for all the flaws that they fix.
  Reply With Quote
Old 12-10-2005, 01:14 PM   #4
xsperf
 
xsperf's Avatar

Name: xsperf
Title: United Baller
Status: Offline
Join Date: Apr 2005
Location: Syracuse, NY
Rate My Car: 183 / 337
Your Ride: 95 325is
what do they mean by "google desktop" ?
__________________

Quote:
Originally Posted by c1apton
I keep forgetting that - I have a great memory but it doesn't last long

CRS disease = Can't Remeber Shit
  Reply With Quote
Old 12-10-2005, 03:07 PM   #5
komodo
 
komodo's Avatar

Name: komodo
Title: Administrator
Status: Offline
Join Date: Apr 2005
Location: Athens, GA
Rate My Car: 71 / 337
Your Ride: 1995 M3
^^ It's a program google has you can install, that basically gives you news headlines and your email and stuff. http://desktop.google.com
__________________

  Reply With Quote
Sponsored Links
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Bush Administration Try To Subpoena Google Records In Porn Probe dinanM6 United Off Topic  **FOR MEMBERS ONLY** 13 01-21-2006 11:55 PM
Google Base komodo United Off Topic  **FOR MEMBERS ONLY** 5 01-20-2006 06:59 PM
The Future of Google: Google Purge komodo United Off Topic  **FOR MEMBERS ONLY** 9 11-28-2005 10:01 PM
Google Launches Firefox Affiliate Program komodo United Off Topic  **FOR MEMBERS ONLY** 7 11-08-2005 08:18 PM
Microsoft vs Google.... now personal. komodo Geek Chat 11 09-04-2005 11:29 PM


All times are GMT -5. The time now is 12:19 AM.

A vBSkinworks Design

 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2010 UnitedBimmer.com
Ad Management by RedTyger
 

Search Engine Optimization by vBSEO 2.4.0 © 2005, Crawlability, Inc.