IE Problem

From: D McAuliffe (DaveMcA_at_mailinator.com)
Date: 12/14/03


Date: Sun, 14 Dec 2003 10:04:09 -0500

The following link: http://dino-soft.org/security/newurlhole.html appears in
the alt.comp.anti-virus NG (DANGEROUS new internet security hole
Sugien). Example 5 was enough to get me to change browsers. Now using
Opera. There's a brew-hah-hah going on about not crediting the origin of
this proof-of-concept (POC) test, but that should not detract from the
seriousness of this security hole. For the average IE user, it is not
enough to practice so called safe-hex in order to prevent ramifications of
this security hole from happening. Although reports of the true link
showing up for a short time in the status bar, only Opera had you go through
a pop up window showing the true server, which you had to OK before being
redirected.
I'm not happy about changing browsers as I don't like going through learning
curves, but not being able to trust a URL is simply unacceptable.

-- 
~~~~~~~~~~~~~~~~~
Dave McAuliffe
Central Mass. USA
To Reply -
  Replace: mailinator.com
  With:      email.com
~~~~~~~~~~~~~~~~~

Loading