Sponsor for PC Pals Forum

Author Topic: IE spoofing flaw adds to Windows' woes  (Read 1689 times)

Offline Clive

  • Administrator
  • *****
  • Posts: 75153
  • Won Quiz of the Year 2015,2016,2017, 2020, 2021
IE spoofing flaw adds to Windows' woes
« on: April 07, 2006, 15:10 »
Joris Evers
CNET News.com
April 07, 2006, 09:15 BST
 
 
A fourth vulnerability in as many weeks has emerged in the most up-to-date versions of the near-ubiquitous browser

An unpatched vulnerability in Internet Explorer could aid fraudsters in pulling off phishing scams, experts have warned.

The error could be exploited to fake the address bar in a browser window, security monitoring company Secunia said in an advisory published on Tuesday. This tactic could be used in phishing scams that attempt to trick people into believing they are on a legitimate site, when in fact they are viewing a fraudulent Web page.

Phishing is a prevalent type of online scam that seeks to pilfer personal information from unsuspecting Internet users. The scams typically combine spam email with fraudulent Web sites that appear to come from a trusted source, such as a credit card company or a bank.

The flaw exists because of an error in the way the Microsoft Web browser loads Web pages and Macromedia Flash animations, according to Secunia. The company rates the issue "moderately critical" and has created a special Web page where users can test their Web browser to see if they are affected.

Secunia has confirmed that the vulnerability affects IE 6.0 on Windows XP with all current security patches. It also affects the latest IE 7 beta, Secunia said. Other versions may also be affected, it said.

Microsoft is investigating the newly reported flaw, the firm said in an emailed statement late Wednesday. "Our initial investigation has revealed that customers who have set their Internet security settings to high, or who have disabled active scripting, are at reduced risk from attack as the attack vector requires scripting," Microsoft said.

Additionally, Microsoft noted that it has not seen any active attacks that take advantage of this issue, which Secunia has dubbed the "Internet Explorer Window Loading Race Condition Address Bar Spoofing" flaw.

This is the fourth unpatched vulnerability for IE that has become public in the last few weeks. Microsoft plans to release a security update for the Web browser on Tuesday. At least one of the disclosed bugs will be fixed in that update, the company has said. That flaw, related to how IE handles the createTextRange() tag in Web pages, has been exploited in attacks to install spyware, remote-control software and Trojan horses on vulnerable PCs.

 http://news.zdnet.co.uk/0,39020330,39261952,00.htm

Offline sam

  • Administrator
  • *****
  • Posts: 19977
IE spoofing flaw adds to Windows' woes
« Reply #1 on: April 07, 2006, 15:13 »
All I am going to say is:

http://www.mozilla.com/firefox/
- sam | @starrydude --

Offline Simon

  • Administrator
  • *****
  • Posts: 77923
  • First to score 7/7 in Quiz of The Week's News 2017
IE spoofing flaw adds to Windows' woes
« Reply #2 on: April 07, 2006, 19:10 »
Indeed!  ;)
Many thanks to all our members, who have made PC Pals such an outstanding success!   :thumb:

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
IE spoofing flaw adds to Windows' woes
« Reply #3 on: April 08, 2006, 06:03 »
The Definition of an Upgrade: Take out old bugs, put new ones in. :laugh:
Those who can make you believe absurdities,
can make you commit atrocities.

Offline sam

  • Administrator
  • *****
  • Posts: 19977
IE spoofing flaw adds to Windows' woes
« Reply #4 on: April 08, 2006, 19:28 »
well an MS update that is!
- sam | @starrydude --

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
IE spoofing flaw adds to Windows' woes
« Reply #5 on: April 09, 2006, 05:03 »
Microsoft motto: We Hav Wurked Outt All tHe buGs.
Those who can make you believe absurdities,
can make you commit atrocities.

Offline sam

  • Administrator
  • *****
  • Posts: 19977
IE spoofing flaw adds to Windows' woes
« Reply #6 on: April 09, 2006, 10:26 »
hehe, i like that!  :laugh:
- sam | @starrydude --


Show unread posts since last visit.
Sponsor for PC Pals Forum