Page 1 of 1

IE7 exploit pool

Posted: Thu Oct 19, 2006 7:49 am
by Patrick
Now that IE7 is officially out we have a pool at work to guess when the first major exploit hits.

I give it 4 weeks

Posted: Thu Oct 19, 2006 11:15 am
by Judland

Posted: Thu Oct 19, 2006 11:20 am
by Patrick
Didn't take long. Let's clarify, a critical security exploit.

Posted: Thu Oct 19, 2006 11:56 am
by snarkout
4 days

Posted: Thu Oct 19, 2006 1:20 pm
by Vogateer
I'll give them three weeks for a critical exploit. They may have actually made some headway.

Posted: Thu Oct 19, 2006 3:57 pm
by jsusanka
2 weeks

Posted: Thu Oct 19, 2006 4:07 pm
by Vogateer
You'd think this were a poker match. I call your bet of 2 weeks. 8)

IE7

Posted: Thu Oct 19, 2006 10:06 pm
by gorkon
Judland gets the bet. This IS a big deal Pat. The bug can cause your paypal signin and password to be revealed as well as credit card info.

http://secunia.com/advisories/22477/

Personally, I don't call this a low bug. It's a critical one. Is it one people are exploiting? Well, probably now that it's been a while.

Posted: Fri Oct 20, 2006 7:09 am
by Brian
I thought IE, by definition, was an exploit.

Re: IE7

Posted: Fri Oct 20, 2006 7:15 am
by Gomer_X
gorkon wrote:Judland gets the bet. This IS a big deal Pat. The bug can cause your paypal signin and password to be revealed as well as credit card info.

http://secunia.com/advisories/22477/

Personally, I don't call this a low bug. It's a critical one. Is it one people are exploiting? Well, probably now that it's been a while.
From what I've read the bug is actually in Outlook Express, but can only be exploited through IE with a redirect. Seems like that's still under debate, though. It's not strictly an IE7 bug.

I'm guessing they've marked it "less critical" because there's an easy workaround (disable active scripting).