Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Bug

IE and Firefox Share a Vulnerability 207

hcmtnbiker writes with news of a logic flaw shared by IE 7 and Firefox 2.0. IE 5.01, IE 6, and Firefox 1.5.0.9 are also affected. The flaw was discovered by Michal Zalewski, and is easily demonstrated on IE7 and Firefox. The vulnerability is not platform-specific, but these demonstrations are — they work only on Windows systems. (Microsoft says that IE7 on Vista is not vulnerable.) From the vulnerability description: "In all modern browsers, form fields (used to upload user-specified files to a remote server) enjoy some added protection meant to prevent scripts from arbitrarily choosing local files to be sent, and automatically submitting the form without user knowledge. For example, '.value' parameter cannot be set or changed, and any changes to .type reset the contents of the field... [in this attack] the keyboard input in unrelated locations can be selectively geared toward input fields by the attacker."
Space

Submission + - A five-gear space rocket engine

Roland Piquepaille writes: "Georgia Tech researchers have had a brilliant idea. Rocket engines used today to launch satellites run at maximum exhaust velocity until they reach orbit. For a car, this would be analog to stay all the time in first gear. So they have designed a new space rocket which works as it has a five-gear transmission system. This space engine uses 40 percent less fuel than current ones by running on solar power while in space and by fine-tuning exhaust velocity. But as it was designed with funds from the U.S. Air Force, military applications will be ready before civilian ones. Here is how this new rocket engine works."

Slashdot Top Deals

Software production is assumed to be a line function, but it is run like a staff function. -- Paul Licker

Working...