There is a great debate on the bugtraq mailing list regarding the apache utf7 xss issue. In this debate William Rowe (Apache) discusses why the Apache utf7 vulnerability is in fact not a vulnerability in Apache but in Internet Explorer for not following specifications properly. William first posted to bugtraq https://seclists.org/bugtraq/2008/May/166 with the following "Internet Explorer's autodetection of UTF-7 clearly violates this specification, introducing the opportunity for myriad similar attacks. These are literally everywhere on the web today, we can trust the kids to continue to explore this vector until it is fixed by Microsoft." What do you think about this debate? Who should be responsible in fixing this vulnerability? This article looks at both side of the debate, letting you decide. . . There is a great debate on the bugtraq mailing list regarding the apache utf7 xss issue. In this deb. there, great, debate, bugtraq, mailing, regarding, apache. . LinuxSecurity.com Team
Striking back against a computer that is attacking you may be illegal under U.S. law, but a security researcher says people should be allowed to neutralize one that is unwittingly spreading destructive Internet worms such as Nimda.. . .. Striking back against a computer that is attacking you may be illegal under U.S. law, but a security researcher says people should be allowed to neutralize one that is unwittingly spreading destructive Internet worms such as Nimda. "Arguably the biggest threat the Internet faces today is the propagation of a big worm," said Timothy Mullen, chief information officer of AnchorIS, at the Defcon hacker conference here. Worms are a form of self-propagating virus that, once set in motion, can wreak havoc by taking control of other machines. Once the virus has claimed a PC, it can then use the machine to launch attacks on the wider Internet. "The next worm is going to happen, and it's going to be worse," Mullen said. The link for this article located at ZDNet / Reuters is no longer available. . Controversy surrounds the notion of countering hostile networks as a legitimate approach to address perilous online bots.. Internet Worms, Cybersecurity Threats, Malware Neutralization, Hacker Conference, Security Research. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.