• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Warp2Search.net » News » March 2007 » New IE7 Bug May Aid Phishers

New IE7 Bug May Aid Phishers

Posted by: [NT] on: 03/14/2007 07:01 PM [ Print | 3 comment(s) ] · 1070 views

Yahoo reports:A vulnerability in Microsoft Corp.'s Internet Explorer (IE) browser could help fraudsters make phishing Web sites appear legitimate, a security researcher reported Wednesday.
The flaw lies in the way IE7 processes a locally stored HTML (Hypertext Markup Language) error message page that is typically shown when the user cancels the loading of a Web page, said Aviv Raff, a security researcher based in Israel.




The error message tells the user that "navigation to the webpage was cancelled," and offers the user the opportunity to "refresh the page." If the refresh link is clicked, IE can be tricked into displaying the wrong Web address for a page. Raff has published proof of concept code that shows how IE can be made to display a Web page on his Web site as if it is from the cnn.com domain.
This flaw could be exploited by phishers who want to make their spoofed Web sites appear legitimate, Raff said.
"I can inject a script that will display anything I want in the page when the user clicks the 'refresh' link," he said via instant message. "Combining this with the design flaw, an attacker can render in the browser whatever he wants with whatever URL he wants in the address bar."
This type of bug is known as a cross-site scripting vulnerability. It affects IE 7 on Vista and Windows XP, Raff added.
Microsoft could not immediately confirm Raff's findings, but the company issued a statement saying that it is investigating the issue and is "not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time."


Digg it! Del.icio.us Technorati Furl Google Bookmarks

« Further AMD next-gen specs roll out · New IE7 Bug May Aid Phishers · CPUCooL 8.0.2 »

Comment

BetrayerX
Unregistered



#66155 Posted on: 03/14/2007 08:17 PM
Any patches, fixes or alternate solutions?

Comment

Omegadrive
Junior Member


Posts: 2
Joined: 2007-10-26

#66156 Posted on: 03/14/2007 11:10 PM
Yep, is called Firefox :D

Comment

3r4s3r
Unregistered



#66159 Posted on: 03/15/2007 09:32 AM
Good one!  ;)

Warp2Search.net » News » March 2007 » New IE7 Bug May Aid Phishers

Latest News

· Corsair TEC-Based Cooling Solution for Memories
· Sony Bravia KDL-52XBR6 Review
· NVIDIAs GeForce GTX 295 In Quad SLI
· nVIDIA GTX260 vs. ATI HD 4870
· CES Day One coverage
· CES 2009 Day 1
· CES 2009 Coverage
· Google Chrome 2.0.156.1
· Simple Port Forwarding 2.2.1
· Here Be Dragons - AMD Phenom II
· Microsoft Security Bulletin Advance Notification for January 2009
· Razer DeathAdder Gaming Mouse for Mac Review
· NZXT Guardian 921 Mid Tower Case Review
· AMD Video BIOS Disassembler Released
· AMD Phenom II X4 940 & 920 Processors Reviewed
· AMD Phenom II X4 940 Review - Not the Second Coming
· BFG GTX 295 Review
· EVGA GeForce GTX 295 SLI Video Card Review
· Thermalright TRUE Copper Heatsink Review
· Nvidia Geforce 3D Vision Review

Nodes To Friends





Online Users

There are currently 620 user(s) online:
Ask Jeeves, Cuil, Google, Live Search, LorD ClockaN, MSN, Yahoo

© 2007-2008 Esselbach Internet Solutions
All products mentioned are registered trademarks or trademarks of their respective owners.
Read our disclaimer over here and our Privacy Policy over here
Managed with Contentteller(R) Business Edition, (C) 2002-2008 Esselbach Internet Solutions