WinXP SP2 is not a panacea, IE has two major vulnerabilities

  
Recently, cyber Flash found two new IE vulnerabilities. Hackers can use these vulnerabilities to bypass Windows XP SP2 security and trick users into downloading malicious code.

Details:


——Windows XP SP2 includes a security feature that warns users when they open certain types of files they download. However, in some cases, if the downloaded file is sent from a specially constructed "Content-Location" HTTP header, the user will not get a system security warning when opening the file.

- use the Javascript function "execCommand ()" when attempting to save some documents, you may get a false file extension in the "Save Html Document" dialog box.

Solution:


- prohibit dynamic script;

- Choose to hide known file extensions.
Copyright © Windows knowledge All Rights Reserved