|
Spoofing Bug Found In MSIE 7 - TechAmok
Spoofing Bug Found In MSIE 7 - [security] 10:49 AM EDT - Oct,26 2006 - post a comment A spoofing bug has been found in IE7.
There is a small video clip of the spoof in action posted in this article,
hit the link and check it out. IE 7, released last week, allows a Web site to
display a pop-up that can contain a spoofed Web address, security monitoring
company Secunia
said Wednesday. An attacker could exploit this weakness to trick people into
believing they are on a trusted Web site when in fact they are viewing a
malicious page, Secunia said in an alert.
The problem lies in the way Web addresses are displayed in the IE 7 address bar, a Microsoft representative said in an e-mailed statement. An attacker could exploit the issue by tricking a user to click on a specially formatted link, the representative said.
The pop-up will block the left part of the Web address, Microsoft said. "Clicking in the browser window or in the address bar and scrolling within it will display the full URL, however," the company said. In case of the Secunia example, the true Secunia URL is revealed.
An attack won't work if a Web site is known to be part of a phishing scam, Microsoft said. The IE 7 phishing shield will identify such sites and warn the user, it said. Microsoft is not aware of any attacks that actually use the reported vulnerability, the company said.
Update (Oct30): It looks like another IE7 pop-up flaw has been found. I am not sure what they mean by "visiting a trusted site that opens a new window with malicious code" or who would even enter their CC info into a pop-up window in the first place but all this info is still good to know.
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
Jul,14 2025 Google Is Selling Fake Products - WAN Show July 11, 2025 Jul,12 2025 Hacked by playing Call of Duty WW2 on Gamepass? Jul,12 2025 2025 VW Golf GTE // TOP SPEED REVIEW on AUTOBAHN Jul,11 2025 NEW Audi RS3 v cheapest used RS3: DRAG RACE Jul,10 2025 A critical security vulnerability in Microsoft Remote Desktop Client Jul,10 2025 Samsung Z Fold/Flip 7 Impressions: Major Upgrades! Jul,08 2025 Gmail's latest feature helps you get rid of those pesky emails from Jul,06 2025 I'm an idiot and still made top 5... here's how Jul,05 2025 The Fantastic Four: First Steps - Official 'Lift Off' Teaser Jul,04 2025 Samsung Galaxy Z Fold 7 - Hands on Look Jul,04 2025 RTX 5070 Ti vs RTX 5080 - Is 5080 Gaming Laptop Worth More $$$? Jul,04 2025 FIRST DRIVE: Praga Bohema - Crazy Hypercar Driven! Jul,03 2025 Ballerina - Exclusive John Wick Deleted Scene (2025) Keanu Reeves, Jul,03 2025 Call of Duty: WWII - Remote Code Execution Warning (PC Game Pass) Jul,02 2025 1014HP Lamborghini REVUELTO 369KMH TOP SPEED POV on AUTOBAHN Jul,01 2025 Nvidia Drivers (V 576.80 vs V 576.88) - Test In 12 Games - RTX 4060 Jun,30 2025 AMD Adrenalin 25.6.3 Driver Is Available Jun,30 2025 NVIDIA GeForce RTX 5080 SUPER Could Feature 24 GB Memory, Increased Jun,29 2025 Guess What Nvidia Did THIS Time Jun,28 2025 The 10 Best Dinosaur Movies of All Time Jun,28 2025 Microsoft officially confirms that Windows 11 version 25H2 is coming Jun,26 2025 Eddington - Official Trailer 2 (2025) Joaquin Phoenix, Pedro Pascal Jun,25 2025 Microsoft Say System Restore Points Now Expire After 60 Days Jun,25 2025 Facebook, Netflix, and Microsoft Websites Hijacked to Insert Fake Jun,24 2025 I put a $3000 GPU in my Average PC... It Was a Mistake Jun,24 2025 Best External SSD for Mac 2025: After Weeks of Testing, Here's What Jun,23 2025 Mostly boob jokes this week (RTX 5090 DD) - Tech News June 22 Jun,21 2025 Superman - Official 30 Second Spot (2025) Jun,21 2025 'The fastest road car I've ever been in!' - Ferrari F80 track day Jun,20 2025 CPU SCAM: AMD Ryzen 9800X3D Counterfeits & Fraud Jun,19 2025 28 Years Later Review Jun,18 2025 HW News - NVIDIA "N1x" CPU Leak, ASUS Xbox ROG Ally, More Intel Jun,17 2025 NVIDIA GeForce 576.80 WHQL Driver Jun,16 2025 The Fantastic Four: First Steps - Official 'H.E.R.B.I.E.' Teaser Jun,15 2025 Huawei Maextro S800 First Look - A True BMW & Mercedes Killer? Jun,14 2025 Upgrade Windows 10 to Windows 10 LTSC Without Losing Data Jun,14 2025 Squid Game: Season 3 - Final Games Trailer Jun,11 2025 WWDC 2025: Everything Revealed in 9 Minutes Jun,10 2025 Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws Jun,10 2025 This Malware BREAKS WINDOWS!
>> News Archive <<
| |
|