Security firm warns of new Internet Explorer flaw, advises ‘use a different browser’
Thursday, July 01, 2004 - 09:42 AM EST"Internet security research group Secunia issued a warning Wednesday about a security vulnerability it says it has discovered within Microsoft's Internet Explorer Web browser. The flaw, which Secunia has ranked as 'moderately critical,' is found within Internet Explorer versions 5.01, 5.5, and 6, Secunia says in an advisory," George V. Hulme reports for InformationWeek.
"Internet Explorer doesn't block malicious Web sites from inserting 'arbitrary content' in an arbitrary frame in a browser window, the Danish security firm says. Secunia says the malicious content will appear as if it originated from a trusted site, which is an attack commonly known as spoofing," Hulme reports.
"Secunia says it has verified the flaw in 'a fully patched Internet Explorer 6 running on Microsoft Windows XP' and that other versions of Internet Explorer could also be affected by this vulnerability. Secunia's only advice is that Internet Explorer users not visit untrusted Web sites or select a different browser," Hulme reports.
Full article here.
MacDailyNews Take: If you're a Mac user still slogging along with Microsoft's Internet Explorer (and our stats tell us there are still some of you out there), are you crazy? Please get with the program. It's called Safari, it's from Apple, and you can download it for free.
Requirements for Safari 1.2:
- Mac OS X 10.3 or later
- Any Macintosh computer
-Requirements for Safari 1.0:
- Mac OS X 10.2 or later
- Any Macintosh computer
More information and download link for Safari here.
MacDailyNews Note: You can use the Safari Debug Menu* to set Safari's User Agent to one of many different browser choices if you need to access sites that are "blocking" Safari. Set your User Agent to "Windows MSIE 6.0" and you'll be amazed at how many of these misguided sites will work with Safari.
*To turn on Safari's Debug Menu, Quit Safari, launch Terminal and type:
defaults write com.apple.Safari IncludeDebugMenu 1
Launch Safari and the Debug Menu will be active.
To turn off Safari's Debug Menu, Quit Safari, launch Terminal and type:
defaults write com.apple.Safari IncludeDebugMenu 0
Launch Safari and the Debug Menu will be inactive.


Wait a minute MS says I need to use MSIE. Many sites use sniffers that will block you if you use a different browser.
What is the average user to do....
All I want to do is check my hotmail....
?