Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

INTERNET EXPLORER

Internet Explorer 8 Critical Zero-Day Security Vulnerability Released in the Wild

- “Courtesy” of Aviv Raff

By: Marius Oiaga, Technology News Editor

It is just a little over two months since the first public testing milestone for Internet Explorer was made available outside of Redmond, and a
critical 0-day security vulnerability impacting the browser has already been released in the wild. Security researcher Aviv Raff has tucked away an exploit somewhere on his blog and issued an invitation for visitors for a little game of vulnerability treasure hunt. According to Raff, both Internet Explorer 7 and Internet Explorer 8 Beta 1 are susceptible to attacks. The researcher stated that he was releasing the vulnerability as part of the celebration of Israel's 60 years of independence.

"As part of the celebration, I’m releasing a new 0day vulnerability. (...) In the spirit of this day, I’ve decided not to release full details about this vulnerability yet, but rather play a little 'treasure hunt' game. Somewhere in my blog, I embedded a proof-of-concept code which exploits this 0day vulnerability," Raff stated.

Microsoft failed to issue an official comment on the IE7 and IE8 Beta 1 vulnerability game, but it seems that so far, none of the visitors to the security researcher's website managed to come across the exploit code. This even if they were supplied with a number of clues to help them identify the attack, including: "IE7.0 and IE8.0b users will get pwned. An interaction with the sploit is needed. There’s no need to find the post. It’s everywhere. 404 is the way to go. Acidus was right! 'Local resources' is the key."

However, Raff is willing to take it a step further. On may 14, 2008, he plans to make public all the details related to the vulnerability. "Next Wednesday I will release the full technical details of this 0day vulnerability and the proof-of-concept code," Raff promised. Of course that the published proof-of-concept will enable all potential attackers to build exploits using the zero day vulnerability and target Internet Explorer 7 and Internet Explorer 8 Beta 1 users.


MORE RELATED ARTICLES: Internet Explorer 8 Beta 1 ActiveX Security Original XP SP3 RTM Integrated Slipstream ISO Images Leaked XP SP3 Ships Complete with a Range of Issues that Survived RTM Mozilla Nearing the Finish Line for Firefox 3.0 IE8 Beta 1 Fixing What's Wrong with IE7 Microsoft Launches IE 8 Beta 1 and IE7 Tree-Hugging Exclusive Website IE8 Beta 2 Will Fix What's Wrong with Beta 1
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


9th May 2008, 13:36 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 1,629 user(s) | Rating: | 3 vote(s) so far | Cast your vote:
Internet Explorer 8 Critical Zero-Day Security Vulnerability Released in the Wild - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Internet Explorer 8 Critical Zero-Day Security Vulnerability Released in the Wild

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive