Advertisement
Promo

Security threats Toolkit

IE bug provides phishing tool

Patrick Gray ZDNet Australia

Published: 10 Dec 2003 09:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A newly discovered bug in Microsoft's Internet Explorer Web browser may help fraudsters trick Internet users into divulging sensitive information and executing malicious code, according to a security researcher.

The new glitch allows a specially crafted URL, or link, to load a browser window that appears to be displaying any address the attacker wants -- this would enable a fraudster to load a window that would appear to be displaying www.zdnet.com.au, for example, but would in fact display content from another source. The problem will make it easier for scammers to trick Internet users into divulging personal details through "phishing scams", where emails purporting to come from the victim's Internet banking provider or another such site encourage them to re-enter details such as usernames and passwords, according to security research engineer Drew Copley.

"You could pretend to be anybody. You could have someone run executable content," he said by phone from the US. "This is not the end of the world [but] it adds to Microsoft's woes."

IE bugs are somewhat of a specialty for Copley, of US-based eEye Digital Security. He has uncovered numerous security issues in the near-ubiquitous Web browser. While the bug may not allow an attacker to compromise a system through a traditional "remote compromise" style of attack, it's the glitch's potential to undermine the users ability to determine what they should trust that represents the largest concern in this instance, he said.

"If [the address is] appearing legitimate like that, you can get people to download anything, run anything, or get a password or whatever," he explained.

However, other, more serious vulnerabilities are more likely to be on the top of Microsoft's hit-list, Copley said; several vulnerabilities were recently discovered by a Chinese security group, with three of them allowing an attacker to remotely compromise a system.

While it's possible for users to mitigate those vulnerabilities by disabling the browser's "active scripting", which allows the browser to run scripts and ActiveX code, turning off the feature will limit the browsers functionality, Copley said.

"You can, of course, turn off active scripting ... it's going to protect you, but it's going to make it hard to browse around," he argued.

The latest glitch was discovered by 18-year-old graphic designer Sam Greenhalgh.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
101 out of 165 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters