hacking security forum

[Full-Disclosure] Re: shell:windows

From: Nick Eoannidis <nikon@xillioncomputers.com>
Date: Sat Jul 10 2004 - 21:43:26 EDT

Larry Seltzer
eWEEK.com Security Center Editor --

buddy, the shell:windows URI handler was disabled in IE ages ago!
The fact it can be crafted into an exploit for Mozilla! is the issue
here.
Of course it wont work on your IE your probably patched to the max!
Mozilla just forgot to disable access to this URI due to the fact
that mozilla was first built for nix and not windoze.
All versions of mozilla have been fixed now

Nikon
Xillion Computers
Trust your Technolust
http://www.xillioncomputers.com
nikon@xillioncomputers.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Received on Sat Jul 10 22:34:27 2004

This archive was generated by hypermail 2.1.8 : Sat Jul 10 2004 - 23:02:37 EDT

Custom Search