proximitum - stress free IT
Proximitum is a software integrator and cloud enabler that provides cloud management and access tools to help organisations manage their adoption of cloud technologies. Proximitum provides hosting and application solutions from a number of independent software vendors (ISVs). These can be procured using our true Software as a Service (SaaS) model.  Find out more
News
04 May 2010

'No risk' for off-site Microsoft SharePoint users

Default security settings in Internet Explorer 8 mean that a reported security issue in Microsoft SharePoint Server 2007 and Microsoft Windows SharePoint
Services 3.0 is already no threat to remote workers, the software developer has revealed.

While the company is already working on a patch to resolve the issue entirely, it has stressed in a Security Advisory notice that remote workers using Internet Explorer 8 should not be at risk.

That is because of the Internet Explorer XSS Filter, which is activated by default for the Internet Zone in the browser and prevents cross-site scripting (XSS) attacks.

Meanwhile, the Microsoft Security Research & Defense blog adds that the risk of anyone being able to exploit the vulnerability - which potentially allows a hacker to gain the same privileges within the relevant Microsoft SharePoint site as the hacked user - is very small.

That is because Microsoft SharePoint authenticates users with HttpOnly cookies, which cannot be accessed through XSS attacks.
ADNFCR-1823-ID-19757712-ADNFCR

discover more
cloud service brokerage l cloud applications l cloud desktops l cloud servers l dedicated infrastructure
Proximitum Ltd, Central Court, 25 Southampton Buildings, London WC2A 1AL. T: 0845 686 9000 F: 0207 907 4790 E: enquiries@proximitum.com
Vat Registered: 860527426 | Company Registration: 05475906
Proximitum on Facebook Proximitum on Twitter Proximitum on YouTube Business Infrastructure Business Communications Business Applications Business Disaster Recovery Professional Services