Want to see a scary IE security bug in action. Try this…
Posted : July 1, 2004 at 2:02 pm [America/Los_Angeles]

…
Test Your Browser1)
Open a trusted site, this could be a bank, ecommerce site, windowsupdate etc. In this example, we have used Microsoft Developer Network. First, click the link below and leave the new window open, then click back to this window.Click Here:
http://msdn.microsoft.com/library/default.aspPlease note, for this example to work in Opera, the browser has to identify itself as “Mozilla” or “Internet Explorer”, because “msdn.microsoft.com” will not return the same content if Opera identifies itself as Opera.
2)
After the other window has been opened, it is possible for another site to inject a page into the “trusted” site’s frameset. In our example, we inject content from Secunia.com into Microsoft.com.Click Here:
Inject Secunia.com into Microsoft.com3)
Now, open the window from Microsoft.com (Opened in step 1), and if your browser is vulnerable, content from Secunia will be displayed in one of the frames.NOTE:
Exploitation can easily be made “automatic”. However, since this example only serves as a test to give users an understanding of how it works, we have chosen not to do so.
…
To really rub it in, Firefox 0.9 (and 0.9.1) is not vulnerable to this in my preliminary tests 
- Anand
Category: Services and Software