ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

IE bug provides phishing tool

Patrick Gray ZDNet Australia

Published: 10 Dec 2003 09:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A newly discovered bug in Microsoft's Internet Explorer Web browser may help fraudsters trick Internet users into divulging sensitive information and executing malicious code, according to a security researcher.

The new glitch allows a specially crafted URL, or link, to load a browser window that appears to be displaying any address the attacker wants -- this would enable a fraudster to load a window that would appear to be displaying www.zdnet.com.au, for example, but would in fact display content from another source. The problem will make it easier for scammers to trick Internet users into divulging personal details through "phishing scams", where emails purporting to come from the victim's Internet banking provider or another such site encourage them to re-enter details such as usernames and passwords, according to security research engineer Drew Copley.

"You could pretend to be anybody. You could have someone run executable content," he said by phone from the US. "This is not the end of the world [but] it adds to Microsoft's woes."

IE bugs are somewhat of a specialty for Copley, of US-based eEye Digital Security. He has uncovered numerous security issues in the near-ubiquitous Web browser. While the bug may not allow an attacker to compromise a system through a traditional "remote compromise" style of attack, it's the glitch's potential to undermine the users ability to determine what they should trust that represents the largest concern in this instance, he said.

"If [the address is] appearing legitimate like that, you can get people to download anything, run anything, or get a password or whatever," he explained.

However, other, more serious vulnerabilities are more likely to be on the top of Microsoft's hit-list, Copley said; several vulnerabilities were recently discovered by a Chinese security group, with three of them allowing an attacker to remotely compromise a system.

While it's possible for users to mitigate those vulnerabilities by disabling the browser's "active scripting", which allows the browser to run scripts and ActiveX code, turning off the feature will limit the browsers functionality, Copley said.

"You can, of course, turn off active scripting ... it's going to protect you, but it's going to make it hard to browse around," he argued.

The latest glitch was discovered by 18-year-old graphic designer Sam Greenhalgh.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
101 out of 162 people found this useful



Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Strong JavaScript Developer / HTML / CSS / Ajax / Cross Browser - ASAP

You will have good experience of Java and Scripting Libraries as well as good working knowledge of Cross Browser Application. I am looking for a ...

Front End Developer - User Interface - Media

If you have knowledge of JavaScript/ DOM Scripting/ AJAX this would be a big advantage. You will have experience creating tableless layouts and cross ...

Database Systems & Integration Developer

You will have a good standard of technical knowledge, including sound scripting skills (VBScript, or equivalent), database administration ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment