Re: SOT: New IE8 Cross Scripting vulnerability

2009-11-25 Thread Joe None
Noscript add on? Can you view, or do, anything on the web? ;) Noscript is a slick add-on I can't live without now. You'd be amazed at how many tracking scripts site attempt to use. Noscript blocks them all as well as the baddies.

Re: SOT: New IE8 Cross Scripting vulnerability

2009-11-25 Thread Dave Watts
Noscript add on? Can you view, or do, anything on the web? ;) I disable scripting all the time, except for sites I trust. Developers should certainly do what they can, but users should be less trusting as well. Dave Watts, CTO, Fig Leaf Software http://www.figleaf.com/ Fig Leaf Software

SOT: New IE8 Cross Scripting vulnerability

2009-11-24 Thread Sandra Clark
Apparently, IE8 has protection that rewrites pages to protect from XSS attacks and there seems to be an issue with it that can actually introduce XSS attacks. http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/

Re: SOT: New IE8 Cross Scripting vulnerability

2009-11-24 Thread Andrew Grosset
another reason why I browse with firefox with the noscript add on. Apparently, IE8 has protection that rewrites pages to protect from XSS attacks and there seems to be an issue with it that can actually introduce XSS attacks.

Re: SOT: New IE8 Cross Scripting vulnerability

2009-11-24 Thread cold.fusion
No, it's one more reason why developers should do what we can, in our development processes, to protect our applications (cfqueryparam, server-side variable validation, etc). Noscript add on? Can you view, or do, anything on the web? ;) Steve Cutter Blades Adobe Certified Professional Advanced