IE7 exploit pool

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

Post Reply
User avatar
Patrick
Site Admin
Posts: 2519
Joined: Tue Apr 27, 2004 11:38 am
Location: Easton, PA
Contact:

IE7 exploit pool

Post by Patrick » Thu Oct 19, 2006 7:49 am

Now that IE7 is officially out we have a pool at work to guess when the first major exploit hits.

I give it 4 weeks
Ego contemno licentia

Judland
Posts: 1030
Joined: Tue Apr 27, 2004 12:55 pm

Post by Judland » Thu Oct 19, 2006 11:15 am


User avatar
Patrick
Site Admin
Posts: 2519
Joined: Tue Apr 27, 2004 11:38 am
Location: Easton, PA
Contact:

Post by Patrick » Thu Oct 19, 2006 11:20 am

Didn't take long. Let's clarify, a critical security exploit.
Ego contemno licentia

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Post by snarkout » Thu Oct 19, 2006 11:56 am

4 days
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

User avatar
Vogateer
Posts: 700
Joined: Thu Nov 17, 2005 11:18 pm
Location: Norman, Oklahoma
Contact:

Post by Vogateer » Thu Oct 19, 2006 1:20 pm

I'll give them three weeks for a critical exploit. They may have actually made some headway.
Vim is beautiful

User avatar
jsusanka
Posts: 306
Joined: Wed Aug 10, 2005 9:24 am
Contact:

Post by jsusanka » Thu Oct 19, 2006 3:57 pm

2 weeks

User avatar
Vogateer
Posts: 700
Joined: Thu Nov 17, 2005 11:18 pm
Location: Norman, Oklahoma
Contact:

Post by Vogateer » Thu Oct 19, 2006 4:07 pm

You'd think this were a poker match. I call your bet of 2 weeks. 8)
Vim is beautiful

User avatar
gorkon
Posts: 116
Joined: Wed May 31, 2006 8:30 am

IE7

Post by gorkon » Thu Oct 19, 2006 10:06 pm

Judland gets the bet. This IS a big deal Pat. The bug can cause your paypal signin and password to be revealed as well as credit card info.

http://secunia.com/advisories/22477/

Personally, I don't call this a low bug. It's a critical one. Is it one people are exploiting? Well, probably now that it's been a while.

User avatar
Brian
Posts: 102
Joined: Tue May 04, 2004 8:07 am
Location: Easton, PA
Contact:

Post by Brian » Fri Oct 20, 2006 7:09 am

I thought IE, by definition, was an exploit.

User avatar
Gomer_X
Posts: 901
Joined: Fri Jun 03, 2005 1:31 pm
Location: Cincinnati, Ohio, USA
Contact:

Re: IE7

Post by Gomer_X » Fri Oct 20, 2006 7:15 am

gorkon wrote:Judland gets the bet. This IS a big deal Pat. The bug can cause your paypal signin and password to be revealed as well as credit card info.

http://secunia.com/advisories/22477/

Personally, I don't call this a low bug. It's a critical one. Is it one people are exploiting? Well, probably now that it's been a while.
From what I've read the bug is actually in Outlook Express, but can only be exploited through IE with a redirect. Seems like that's still under debate, though. It's not strictly an IE7 bug.

I'm guessing they've marked it "less critical" because there's an easy workaround (disable active scripting).

Post Reply