Zoomorama Developers' Blog

The Art of Zooming

To content | To menu | To search

Tag - IE8

CVE-2009-4074

"Related to the details of output encoding". Encoding? Really? Neither Maone nor the Register mention encoding IIRC, and they are the only sources mentioned....

Continue reading

IE8 XSS Filter flaw?

It seems that IE8 XSS Filter has a bug making otherwise safe sites vulnerable to XSS (if they don't opt-out the feature). While the Register post is less than informative, this is reported as well by...

Continue reading

IE8 XSS Protection, part 2

Paul twitted a former entry of this blog about the IE8 XSS filter, subsequently attracting reactions on this otherwise very quiet blog :-). As the post in question was a typical trollish rant of me,...

Continue reading

IE8 XSS "Protection"

So, it appears IE8 introduced a brand new XSS protection mechanism. It apparently does so by inspecting javascript resources and modifying them before execution. So long, so good? Well... apparently,...

Continue reading