| IE8 Vulnerability Already Discovered |
| Written by Ryan Naraine | |||
| Friday, 20 March 2009 01:10 | |||
|
It took a while longer but Microsoft’s Internet Explorer 8 did not survive the hacker onslaught at this year’s CanSecWest Pwn2Own contest. A security researcher named “Nils” (he declined to provide his full name) performed a clean drive-by download attack against the world’s most widely used browser to take full control of a Sony Vaio machine running Windows 7. He won a cash prize and got to keep the hardware. Details of the vulnerability, which was described by contest sponsor TippingPoint ZDI as a “brilliant IE8 bug!” are being kept under wraps. Several members of Microsoft’s security response team were on hand to witness the successful exploit. “Nils” also scored a clean hit against Apple’s Safari (he was the second hacker to exploit Safari) and, later in the afternoon, he exploited a Firefox zero-day flaw to claim the trifecta. {mosgoogle}
The long awaited final version of Microsoft Internet Explorer 8 final has gone live. Here are the download links:
|
| --BEGIN GEEK CODE BLOCK-- GE/CS d++ s:++>: a+ C++ LU--- P++ L+ E---W++(+) N++ o-- K w++ O--- M-- V PS PE Y PGP- t++ 5X++ R->$ tv- b+ DI++ D G+ e++ h--- r+++ z+++ --END GEEK CODE BLOCK-- |