Skip to main content

Browsers Still Vulnerable to Command Injection Attacks, Hackers Say

posted onOctober 21, 2007
by hitbsecnews

Nathan McFeters and Rob Carter want you to know that it's not over - even if an initial fix to block command injection attacks was released in the last few days.

"It's not done. There's going to be more stack overflows, more ccommand injections," McFeters says. "It gets scarier as you go on. We want to make third party developers aware that when you register URI you are creating an attack environment."

Firefox and Netxcape Navigator 9 register URIs to be compliant with Windows Vista, so they are now vulnerable to command injection when called from the IE, says Rob Carter, who with McFeters runs the xs-sniper.com site where this is discussed in detail.

Source

Tags

Security

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th