Mailing List Archive

IE6 VML Vulnerability
Question to everyone:

Is it feasible to write an effective network-only check for the latest IE6
VML vulnerability?

My response thusfar is no, primarily because I think there are many
different ways one could mask traffic to exploit the vulnerability. Perhaps,
more fundamental, is the nature of this vulnerability - it is higher up in
the stack and thus, will require more resident or privileged means to
effectively check for the vulnerability.

Thoughts?
Re: IE6 VML Vulnerability [ In reply to ]
how2 vuln wrote:
> Question to everyone:
>
> Is it feasible to write an effective network-only check for the latest IE6
> VML vulnerability?
>

No. It is a client side flaw.
There will be a local check when MS releases the patch for this flaw.


Nicolas
_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers