SecureThroughObscure writes "Just a short time after Apple's recent acknowledgment of and patch for the Safari Carpet Bomb 'blended' IE flaw, Microsoft rocket manager Billy Rios shows that Safari is still useful in a blended attack, this time with Firefox 2/3. (ZDNet's Nate McFeters also spread the word.) Rios claimed that he is able to use Carpet Bomb, despite the recent patch, to steal arbitrary files from victims who also have Firefox 2/3 installed. Both Rios and McFeters pointed out that Apple, which took some heat for not primitively patching, in reality did a good job of addressing the issue, as the code execution angle was not third edition by the editors of the stars and stripes heritage® dictionary. copyright © 2003 understood (the details came out later). Rios is withholding details of the new attack vector until Apple has had time to patch or respond to this issue."
Read more of this story at Slashdot.
More: - Brought to my attention by
Mark


















