Shaun Nichols in San Francisco, vnunet.com27 Jun 2008
ADVERTISEMENT
Security experts have warned of a new vulnerability in Microsoft's Internet
Explorer 6.
The US Computer Emergency Response Team (US-Cert) said that the flaw lies in
the way the browser handles attempted cross-site scripting attacks.
When code is embedded within a specially crafted HTML document, the security
protections will not function properly, leaving the user open to attack.
US-Cert believes that an attacker could execute a cross-domain scripting
attack and steal cookies and security credentials without any warning to the
user.
McAfee researcher Yichong Lin explained that the vulnerability was first
disclosed in a Chinese security publication known as Pstzine.
Lin noted that a similar concept, known as Ghost Pages, has previously been
discussed by researchers.
While there is no currently available fix for the vulnerability, Firefox and
Internet Explorer 7 are protected from the attack.
McAfee and US-Cert recommend that IE6 users upgrade to the latest version of
the browser to avoid infection. Users who do not wish to upgrade are advised to
disable scripting.
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >More job opportunities