<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>andagree &#187; Internet Explorer</title>
	<atom:link href="http://andagree.wordpress.com/category/internet-explorer/feed/" rel="self" type="application/rss+xml" />
	<link>http://andagree.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Thu, 15 May 2008 22:55:51 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='andagree.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/4d5fcc6fd175eee8118075d0e013f6bb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>andagree &#187; Internet Explorer</title>
		<link>http://andagree.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://andagree.wordpress.com/osd.xml" title="andagree" />
		<item>
		<title>Zero-Day Internet Explorer Vulnerability Published</title>
		<link>http://andagree.wordpress.com/2008/05/15/zero-day-internet-explorer-vulnerability-published/</link>
		<comments>http://andagree.wordpress.com/2008/05/15/zero-day-internet-explorer-vulnerability-published/#comments</comments>
		<pubDate>Thu, 15 May 2008 22:55:51 +0000</pubDate>
		<dc:creator>andagree</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Explorer]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Published]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://andagree.wordpress.com/?p=17</guid>
		<description><![CDATA[Israeli security researcher Aviv Raff on Wednesday published details about a zero-day vulnerability in Microsoft (NSDQ: MSFT) Internet Explorer.
Last week, Raff held a &#8220;treasure hunt&#8221; on his site, where he had hidden the exploit code. He declared &#8220;George the Greek&#8221; the contest winner in conjunction with the publication of details about the vulnerability.
More Internet InsightsWhite [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andagree.wordpress.com&blog=524657&post=17&subd=andagree&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="color:#000000;">Israeli security researcher Aviv Raff on Wednesday published details about a zero-day vulnerability in Microsoft (NSDQ: MSFT) Internet Explorer.<br />
Last week, Raff held a &#8220;treasure hunt&#8221; on his site, where he had hidden the exploit code. He declared &#8220;George the Greek&#8221; the contest winner in conjunction with the publication of details about the vulnerability.</span></p>
<p><span style="color:#000000;">More Internet InsightsWhite PapersThe 9 Noble Truths of Custom Experience: Website Wisdom for Everyone in the Organization Pro Football Team Improves Connection With Fans Through New Social Networking Site Prime Indian Securities Trading Site Moves to Web 2.0, Achieves Lead Generation Boost &#8220;Internet Explorer is prone to a Cross-Zone Scripting vulnerability in its &#8216;Print Table of Links&#8217; feature,&#8221; Raff explained in a post on Milw0rm.com summarizing his proof-of-concept exploit. &#8220;This feature allows users to add to a printed Web page an appendix which contains a table of all the links in that Web page.&#8221;<br />
According to Raff, an attacker can add a maliciously crafted link to any Web page that accepts user generated content that, under certain circumstances, lets the attacker take control of the user&#8217;s machine when he or she tries to print the page.<span id="more-17"></span></span></p>
<p><span style="color:#000000;">When it prints a page, </span><a href="http://www.annunci-qui.com/"><span style="color:#000000;">Internet</span></a><span style="color:#000000;"> Explorer invokes a local resource script to generate any of the HTML to be printed. &#8220;This HTML consists of the following elements: Header, webpage body, footer, and if enabled, also the table of links in the Web page,&#8221; Raff explains.</span></p>
<p><span style="color:#000000;">Because the script does not validate the URL, an attacker can inject a script that will be executed when the HTML to be printed is generated.</span></p>
<p><span style="color:#000000;">Users of Internet Explorer 7.0 and 8.0b on fully patched Windows XP systems are vulnerable. Users of Windows Vista with User Account Control (UAC) enabled may only be subject to information leakage. Earlier versions of Internet Explorer may also be affected.</span></p>
<p><span style="color:#000000;">Raff said that he alerted Microsoft to the problem on Tuesday and that the company is planning a fix. In the meantime, he advises not using the &#8220;Print Table of Links&#8221; feature when printing Web pages.</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/andagree.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/andagree.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andagree.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andagree.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andagree.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andagree.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andagree.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andagree.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andagree.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andagree.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andagree.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andagree.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andagree.wordpress.com&blog=524657&post=17&subd=andagree&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://andagree.wordpress.com/2008/05/15/zero-day-internet-explorer-vulnerability-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/affc825cf792c962c27493771ec79fd1?s=96&#38;d=identicon" medium="image">
			<media:title type="html">andagree</media:title>
		</media:content>
	</item>
	</channel>
</rss>