@bartblaze Using Metasploit, CVE-2014-0307 still owns the user despite CV. But CVE-2014-0322 fails with CV, I even removed ua_ver check.
-
-
Replying to @markloman
@markloman Interesting indeed! Conclusion: don't use CV. (or IE) :D1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@markloman I am pretty confident you can even config your site to request compatibility view from visitors' IE...1 reply 0 retweets 0 likes -
Replying to @akaasjager
@akaasjager@bartblaze oeh! that is interesting! https://msdn.microsoft.com/en-us/en-en/library/cc817574.aspx … this could be a potential gold mine for attackers1 reply 0 retweets 0 likes -
Replying to @markloman
@markloman@bartblaze it is, isn't it? "EmulateIE7" and weeeee.1 reply 0 retweets 0 likes
Replying to @akaasjager
@akaasjager @markloman Oh for sure that is perfectly possible. This also means there's a heightened attack surface as well.
12:30 AM - 28 Jul 2015
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.