Pwn2Own駭客大會Safari及IE 8首日就被攻陷

多說無義 看看各家瀏覽器(正式+最新bata)漏洞 至今天3/28還沒補洞數(來源secunia)

補洞不積極 被攻陷也是應該的

Vulnerability Report: Mozilla Firefox 3.x
This vulnerability report for Mozilla Firefox 3.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

Vendor Mozilla Organization

Product Link View Here (Link to external site)


Affected By 12 Secunia advisories
56 Vulnerabilities


Monitor Product Receive alerts for this product


Unpatched 17% (2 of 12 Secunia advisories)




Vulnerability Report: Opera 9.x
This vulnerability report for Opera 9.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Opera 9.x then you are more than welcome to contact us.

Vendor, Links, and Unpatched Vulnerabilities
Vendor Opera Software


Product Link View Here (Link to external site)


Affected By 22 Secunia advisories
50 Vulnerabilities


Monitor Product Receive alerts for this product


Unpatched 0% (0 of 22 Secunia advisories)



Vulnerability Report: Safari 3.x
This vulnerability report for Safari 3.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Safari 3.x then you are more than welcome to contact us.


Vendor, Links, and Unpatched Vulnerabilities
Vendor Apple


Product Link View Here (Link to external site)


Affected By 7 Secunia advisories
27 Vulnerabilities


Monitor Product Receive alerts for this product


Unpatched 14% (1 of 7 Secunia advisories)



Vulnerability Report: Google Chrome 1.x
This vulnerability report for Google Chrome 1.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Google Chrome 1.x then you are more than welcome to contact us.


Vendor, Links, and Unpatched Vulnerabilities
Vendor Google


Product Link View Here (Link to external site)


Affected By 2 Secunia advisories
3 Vulnerabilities


Monitor Product Receive alerts for this product


Unpatched 0% (0 of 2 Secunia advisories)
又一個標題殺人法....

說的好像只有這兩個瀏覽器有問題一樣....
沒有一種瀏覽器是安全的
只有不斷更新漏洞才是最好的辦法
IE不是爛,
只是補漏洞的速度比烏龜慢,
而且老是搞自閉的規格,
害一些網站非IE才能開,
看的就很火,
就方便性來說,
我現在都用火狐,
還一堆方便的plugins,
IE現在只有用網路ATM才會用了。
蘋果飯 wrote:
文章沒看仔細
Chrome的漏洞有找到
上屆Pwn2Own大賽冠軍得主Charlie Miller表示,雖然他的確在Google Chrome中找到了安全漏洞,但卻因為該瀏覽器將沙箱(Sandbox)功能與Windows 7的安全措施結合在一起,而無法成功。
這個我有看到 ... 但最後一樣還是沒破解成功, 不是嗎?
即然沒破解 ... 我認為就不算 bug
gogmaog wrote:
IE不是爛,只是補漏...(恕刪)
都嘛是 Microsoft 搞了個 ActiveX 出來
雖然有人寫出可以讓 Firefox 支援 ActiveX 了... 但也不是全部都能用
印象中看過一篇文章,說一年累計下來firefox漏洞比IE多,但是firefox補洞比IE快
dm77 wrote:
看過一篇文章,說一年累計下來firefox漏洞比IE多,但是firefox補洞比IE快


有...是奇摩新聞前幾個禮拜寫到的..
01不給改暱稱,請叫我柚子 Blog: http://www.3cblog.idv.tw
gogmaog wrote:
而且老是搞自閉的規格,


搞自閉的規格是網頁程式設計師的錯,而不是微軟的錯
大部份都只針對IE開發
如果當初大家都針對NETSCAPE開發,今天的局面應該大為不同

會變成NETSCAPE搞自閉的規格喔
s8726413 wrote:
搞自閉的規格是網頁程...(恕刪)
這是完全顛倒的思考模式...

由於 IE 解讀網頁的方式與眾不同,所以網頁程式設計師必須針對 IE 加以 hack 之後,IE 才能正確顯示、排版『符合標準規格的網頁』,這不是微軟的問題是誰的問題?

而要不是當初微軟將 IE 榜在 Windows 上,以此大敗 Netscape,使得 IE 獨霸瀏覽器市場這麼多年,讓 IE 變成『偽標準規格』,那麼哪會有那麼多網頁設計師設計那些只有 IE 能夠讀取的網頁?
文章分享
評分
評分
複製連結

今日熱門文章 網友點擊推薦!