PogoWasRight.org

Menu
  • About
  • Privacy
Menu

IE Windows vuln coughs up local files

Posted on January 27, 2010 by pogowasright.org

Dan Goodin reports:

If you use any version of Internet Explorer to surf Twitter or other Web 2.0 sites, Jorge Luis Alvarez Medina can probably read the entire contents of your primary hard drive.

The security consultant at Core Security said his attack works by clicking on a single link that exploits a chain of weaknesses in IE and Windows. Once an IE user visits the booby-trapped site, the webmaster has complete access to the machine’s C drive, including files, authentication cookies – even empty hashes of passwords.

Read more in The Register.

Category: Online

Post navigation

← Barnes & Noble Reassures Customers That It Has Never Shared Credit Card Information with Discount Clubs
Happy Data Privacy Day! →

1 thought on “IE Windows vuln coughs up local files”

  1. concerned says:
    January 27, 2010 at 11:29 pm

    Oh goodie.

    It seems that the only way to keep my data safe is to have one machine with data and another with internet connectivity (for surfing).

Comments are closed.

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data
  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data

RSS Recent Posts on DataBreaches.net

  • CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup
  • Montana Attorney General launches investigation into Lee Enterprises data breach
  • AT&T gets preliminary approval for $177 million data breach settlement
  • Aflac notifies SEC of breach suspected to be work of Scattered Spider
  • Former JBLM soldier pleads guilty to attempting to share military secrets with China
©2025 PogoWasRight.org. All rights reserved.