<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	<title>MetaFilter posts tagged with flaw</title>
	<link>http://www.metafilter.com/tags/flaw</link>
	<description>Posts tagged with 'flaw' at MetaFilter.</description>
	<pubDate>Tue, 16 Dec 2008 02:33:52 -0800</pubDate> <lastBuildDate>Tue, 16 Dec 2008 02:33:52 -0800</lastBuildDate>

	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>
	<item>
		<title>Zero-Day</title>
		<link>http://www.metafilter.com/77470/ZeroDay</link>
		<description> BBC: Users of the world&apos;s &lt;a href=&quot;http://news.bbc.co.uk/1/hi/technology/7784908.stm&quot;&gt;most common web browser&lt;/a&gt; (good old &lt;a href=&quot;http://www.microsoft.com/windows/products/winfamily/ie/default.mspx&quot;&gt;IE&lt;/a&gt;!) have been advised to switch to a rival until &lt;a href=&quot;http://www.vnunet.com/vnunet/news/2232403/ie-zero-day-emerges&quot;&gt;a serious security flaw&lt;/a&gt; has been fixed. &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/961051.mspx&quot;&gt;Microsoft Security Advisory 961051&lt;/a&gt;. &lt;a href=&quot;http://oss.itproportal.com/articles/2008/12/16/internet-explorer-7-records-huge-increase-hacking-attacks/&quot;&gt;Microsoft Corp. has tipped off its users of a &#8220;huge increase&#8221; in hacking attacks&lt;/a&gt; exploiting a critical unpatched vulnerability in some versions of its flagship web-browser Internet Explorer (IE), and notified that some of these attacks have originated from hacked porn websites. 

In addition to IE7, other versions like IE 5 and IE 6 have also been found to be vulnerable to the flaw, which on proper exploitation could enable a hacker to seize complete control over victim&#8217;s computer, the company added. 

The flaw essentially originates from the improper handlings of DHTML data bindings due to a memory corruption error.  Though the hackers have been exploiting the vulnerability for more than a week, the company notified an upswing in attacks over the weekend. 

Researchers Tareq Saade and Ziv Mador in one of their postings on Malware Protection Center blog said, &#8220;Based on our stats, since the vulnerability has gone public, roughly 0.2 percent of users worldwide may have been exposed to websites containing exploits of this latest vulnerability&#8221;. 

The researchers purported that the hackers have now changed their methodology of attacks, as instead of using malicious websites for attacks, they are now using compromised legitimate websites to trick the users. 

Incidentally Trend Micro Inc has estimated that around 6,000 websites have been infected so far to exploit the vulnerability, with the count &#8220;quickly increasing in number&#8221;. </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.77470</guid>
		<pubDate>Tue, 16 Dec 2008 02:33:52 -0800</pubDate>
		<category>chrome</category>
		<category>explorer</category>
		<category>firefox</category>
		<category>flaw</category>
		<category>IE</category>
		<category>internet</category>
		<category>internetexplorer</category>
		<category>microsoft</category>
		<category>mozilla</category>
		<category>opera</category>
		<category>safari</category>
		<category>sercurity</category>
		<category>shit</category>
		<dc:creator>chuckdarwin</dc:creator>
	</item>
      <item>
		<title>And DJB&apos;s $500 is safe for another day</title>
		<link>http://www.metafilter.com/73180/And%2DDJBs%2D500%2Dis%2Dsafe%2Dfor%2Danother%2Dday</link>
		<description> &lt;a href=&apos;http://blogs.zdnet.com/security/?p=1460&apos;&gt;A major flaw in the DNS system&lt;/a&gt; is promised to be revealed at the next &lt;a href=&apos;http://www.blackhat.com/&apos;&gt;Black Hat conference&lt;/a&gt;. Convinced it was too important to wait, security researcher &lt;a href=&apos;http://video.google.com/videoplay?docid=3470502418262982787&apos;&gt;Dan Kaminsky&lt;/a&gt; &lt;small&gt;(video, autoplays)&lt;/small&gt; convinced &lt;a href=&apos;http://www.microsoft.com/technet/security/Bulletin/MS08-037.mspx&apos;&gt;several&lt;/a&gt; &lt;a href=&apos;http://www.cisco.com/warp/public/707/cisco-sa-20080708-dns.shtml&apos;&gt;software&lt;/a&gt; &lt;a href=&apos;http://sunsolve.sun.com/search/document.do?assetkey=1-26-239392-1&apos;&gt;vendors&lt;/a&gt; to issue emergency patches today, before publicizing details of the attack. &lt;a href=&apos;http://blogs.zdnet.com/security/?p=1466&apos;&gt;It can&apos;t be that serious though, can it&lt;/a&gt;? &lt;a href=&apos;http://www.matasano.com/log/1093/patch-your-non-djbdns-server-now-dan-was-right-i-was-wrong/&apos;&gt;Oh yes it can&lt;/a&gt;.  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.73180</guid>
		<pubDate>Wed, 09 Jul 2008 18:57:48 -0800</pubDate>
		<category>attack</category>
		<category>dankaminsky</category>
		<category>dns</category>
		<category>exploit</category>
		<category>flaw</category>
		<category>hack</category>
		<category>vulnerability</category>
		<dc:creator>Skorgu</dc:creator>
	</item>
      <item>
		<title>Wikipedia impartiality</title>
		<link>http://www.metafilter.com/58022/Wikipedia%2Dimpartiality</link>
		<description>&lt;a href="http://www.cnn.com/2007/TECH/internet/01/24/microsoft.wikipedia.ap/index.html"&gt;Microsoft has been caught paying for Wikipedia edits.&lt;/a&gt; But wasn&apos;t this inevitable? Now that Wikipedia has become the &lt;em&gt;de facto&lt;/em&gt; online reference, wasn&apos;t it inevitable that it would attract governments, corporates and other groups to create their own version of events. Is this an inherent and fatal flaw in open source knowledge?  </description>
		<guid isPermaLink="false">tag:metafilter.com,2007:site.58022</guid>
		<pubDate>Wed, 24 Jan 2007 12:42:30 -0800</pubDate>
		<category>flaw</category>
		<category>ibm</category>
		<category>impartial</category>
		<category>microsoft</category>
		<category>wikipedia</category>
		<dc:creator>bobbyelliott</dc:creator>
	</item>
      
	</channel>
</rss>


