Simon Willison’s Weblog

Subscribe

Sunday, 22nd November 2009

Major IE8 flaw makes ’safe’ sites unsafe. IE8 has an XSS protection feature which rewrites potentially harmful code in HTML pages—I think it looks for suspicious input in query strings which appears to have been output directly on the page. Unfortunately it turns out there’s a flaw in the feature that can allow attackers to rewrite safe pages to introduce XSS flaws. Google are serving all of their pages with the X-XSS-Protection: 0 header. Until the fix is released, that’s probably a good idea.

# 3:34 pm / ie8, microsoft, security, vulnerability, xss, xssfilter

IE 6 and 7 hit by hack attack code. IE6 and 7 have what looks like a buffer overflow vulnerability caused by a strange intersection of CSS, innerHTML and large JavaScript arrays. No exploits in the wild yet but it’s only a matter of time.

# 3:38 pm / ie6, ie7, microsoft, security

2009 » November

MTWTFSS
      1
2345678
9101112131415
16171819202122
23242526272829
30