• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Warp2Search.net » News » March 2007 » New IE7 Bug May Aid Phishers

New IE7 Bug May Aid Phishers

Posted by: [NT] on: 03/14/2007 07:01 PM [ Print | 3 comment(s) ] · 1632 views

Yahoo reports:A vulnerability in Microsoft Corp.'s Internet Explorer (IE) browser could help fraudsters make phishing Web sites appear legitimate, a security researcher reported Wednesday.
The flaw lies in the way IE7 processes a locally stored HTML (Hypertext Markup Language) error message page that is typically shown when the user cancels the loading of a Web page, said Aviv Raff, a security researcher based in Israel.




The error message tells the user that "navigation to the webpage was cancelled," and offers the user the opportunity to "refresh the page." If the refresh link is clicked, IE can be tricked into displaying the wrong Web address for a page. Raff has published proof of concept code that shows how IE can be made to display a Web page on his Web site as if it is from the cnn.com domain.
This flaw could be exploited by phishers who want to make their spoofed Web sites appear legitimate, Raff said.
"I can inject a script that will display anything I want in the page when the user clicks the 'refresh' link," he said via instant message. "Combining this with the design flaw, an attacker can render in the browser whatever he wants with whatever URL he wants in the address bar."
This type of bug is known as a cross-site scripting vulnerability. It affects IE 7 on Vista and Windows XP, Raff added.
Microsoft could not immediately confirm Raff's findings, but the company issued a statement saying that it is investigating the issue and is "not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time."


Digg it! Del.icio.us Technorati Furl Google Bookmarks

« Further AMD next-gen specs roll out · New IE7 Bug May Aid Phishers · CPUCooL 8.0.2 »

Comment

BetrayerX
Unregistered



#66155 Posted on: 03/14/2007 08:17 PM
Any patches, fixes or alternate solutions?

Comment

Omegadrive
Unregistered



Posts: 0
Joined: 2007-10-26

#66156 Posted on: 03/14/2007 11:10 PM
Yep, is called Firefox :D

Comment

3r4s3r
Unregistered



#66159 Posted on: 03/15/2007 09:32 AM
Good one!  ;)

Warp2Search.net » News » March 2007 » New IE7 Bug May Aid Phishers

Latest News

· SUPERAntiSpyware 4.31.1000
· XP-Antispy 3.97-6
· Apple's Share of Worldwide Smartphone Ad Requests Hits 50%
· Microsoft Expression Web 3 Service Pack 1
· Trendnet 300Mbps Wireless N Travel Router Review
· Seven Cheap Full HD 22-inch Monitors Review
· BlackBerry Master Control Program (Stand Alone) 0.9.2.0
· Seagate BlackArmor NAS 110 1TB NAS Box Review
· Crucial Ballistix Tracer DDR3-1333 RAM Review
· Corsair HX650W Power Supply Review
· SUPERAntiSpyware 4.31.1000 Beta
· ASUS P7H57D-V EVO motherboard: First look in pictures
· Recuva (Slim) 1.33.451
· ZipGenius 6.2.0.2003
· AMP 4GB USB Drives Review
· Trend Micro RootkitBuster 2.80.1077
· OCZ DDR3 PC3-15000 Platinum Series 4GB Memory Kit Review
· NZXT Gamma Gaming Case Review

Community Forum

· S.T.A.L.K.E.R.: Call of Pripyat Benchmark
Posted by Regeneration

· Thermaltake BlacX Duet Dual Hard Drive Docking Station Review @ Tweaknews
Posted by Tweaknews

· Noctua NH-D14 Premium CPU Cooler Review @ Clunk.org.uk
Posted by Clunk

· HIS Radeon HD4850 iCooler 1GB Videocard Review @ Tweaknews
Posted by Tweaknews

· Building An Ultimate Gaming Machine!
Posted by ezone


Nodes To Friends





Online Users

There are currently 482 user(s) online:
Ask Jeeves, Cuil, Google, Live Search, MSN, Yahoo

© 2007-2009 Esselbach Internet Solutions
All products mentioned are registered trademarks or trademarks of their respective owners.
Read our disclaimer over here and our Privacy Policy over here
Managed with Contentteller(R) Business Edition, (C) 2002 - 2009 Esselbach Internet Solutions