On CHOW: Throw parties like a pro
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 2 of 60:
Next »
« Previous
So in the end, Mozilla fixes it in 7 days...
... whilst Microsoft takes..... 7 weeks? 7 months? 7 years? Never?

"the called app needs to do its own data verification"

This is true, but obviously whole swathes of possible attacks can be eliminated through correct escaping.


"what MS (and every coder in the talkbacks) has said all along? "

Coders are always responsible for what the code and that includes MS. Mozilla has shown the way.
Posted by: bportlock   Posted on: 07/31/07 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

So in the end, Mozilla admits  No_Ax_to_Grind | 07/31/07
So in the end, Mozilla fixes it in 7 days...  bportlock | 07/31/07
Reading is fundemental... There was no "fix".  No_Ax_to_Grind | 07/31/07
They also said...  bportlock | 07/31/07
Small hoile, big hole, its still a hole.  No_Ax_to_Grind | 07/31/07
Same vulnerability...  jasonp@... | 07/31/07
Because it is NOT a bug.  No_Ax_to_Grind | 07/31/07
No_Ax you are right it's not a bug , it's a feature .  MythBuster | 07/31/07
re: Small hoile, big hole, its still a hole.  MythBuster | 07/31/07
Call it a lesson learned  Michael Kelly | 07/31/07
But it is not fixed.  No_Ax_to_Grind | 07/31/07
Do us the favour of being honest with us  bportlock | 07/31/07
Gee, is that your best thought out post?  No_Ax_to_Grind | 07/31/07
No - it is just a statement of how you appear to behave  bportlock | 07/31/07
Judging from the quality (or lack of) of your posts.  No_Ax_to_Grind | 07/31/07
Just one question  zkiwi | 08/01/07
Misrepresentation is pathetic  Freebird54 | 08/01/07
You almost have it  magcomment | 07/31/07
More to it.  No_Ax_to_Grind | 07/31/07
Re: How would the OS or even IE know what is correct and what isn't?  Kid Icarus-21097050858087920245213802267493 | 07/31/07
... so use a schema  Downsider | 08/01/07
So the vulnerability is still there, but the Firefox vector is closed  WiredGuy | 07/31/07
Sorry you are wrong, read the article.  No_Ax_to_Grind | 07/31/07
So you admit...  jasonp@... | 07/31/07
NO! It is not...  No_Ax_to_Grind | 07/31/07
Ahhh....  jasonp@... | 07/31/07
Its what I have said all along, even when FF blamed MS  No_Ax_to_Grind | 07/31/07
Not what he said  rapson | 07/31/07
You forget to try and explain  zkiwi | 08/01/07
Having read all your replies to this post...  Logics | 07/31/07
So I (you, whoever) write a malware plug in  No_Ax_to_Grind | 07/31/07
Why do I bother?  Logics | 07/31/07
He gets it, doesn't care  TripleII | 07/31/07
Don Rupert *never gets it*  DonRupertBitByte | 07/31/07
You're right , Mozilla did admit to the flaw .  MythBuster | 07/31/07
I don't see a link for the FF update  BillyG_n_SC | 07/31/07
Err...  bportlock | 07/31/07
Just got it on mine  Michael Kelly | 07/31/07
That's so, 30 seconds ago  Mike Hunt | 08/01/07
yea, but you know the deal...  BillyG_n_SC | 07/31/07
If you don't want to wait...  dragosani | 07/31/07
Bill...  Monkey_MCSE | 07/31/07
I know that people...  BillyG_n_SC | 07/31/07
For Instance  Max_in_OH | 07/31/07
Like a Curate's egg, it is good in bits.  bportlock | 07/31/07
I pose a question to Axey  Shelendrea | 07/31/07
Because there really is no way to fix it.  No_Ax_to_Grind | 07/31/07
Wait a second  Kid Icarus-21097050858087920245213802267493 | 07/31/07
One more time  No_Ax_to_Grind | 07/31/07
What about this  Shelendrea | 07/31/07
C'mon,  Kid Icarus-21097050858087920245213802267493 | 07/31/07
The Fix is . . .  JLHenry | 08/01/07
Those who disagrees with No_Ax,  Grayson Peddie | 07/31/07
Not really  DonRupertBitByte | 07/31/07
Indeed, its the apps responsibility  No_Ax_to_Grind | 07/31/07
It is a matter of the incorrect app being called...  Logics | 07/31/07
INcorrect  Freebird54 | 08/02/07
NO MORE APPROVAL DIALOGS  Resuna | 07/31/07
I agree  TripleII | 07/31/07
2.0.0.6 broke things too!  robo3 | 08/01/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

SmartPlanet

Click Here