ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft update ignores spoofing hole

Munir Kotadia ZDNet.co.uk

Published: 14 Jan 2004 17:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft released three patches on Tuesday to fix a number of security flaws, but surprised users by not releasing a patch for an Internet Explorer vulnerability that helps criminals steal users' identities and commit banking fraud.

The Internet Explorer vulnerability, which was first discovered in early December, allows the browser window to display an URL in the address tab while actually connecting to a different Web site altogether. On Monday, separate emails targeting Barclays and Lloyds TSB's online-banking customers attempted to exploit the flaw and steal customers' passwords.

However, Microsoft is not yet convinced that there is a serious problem and has so far refused to say when a fix will be released. A Microsoft spokesperson told ZDNet UK that the company is "aggressively investigating" the problem and will take "the appropriate action" on completion of its investigation. The company did admit that "it may be possible for an attacker to display misleading information" but denied the flaw was being actively exploited: "Microsoft is monitoring the situation closely but at this time has no indication of widespread usage of the vulnerability," the spokesperson said.

Microsoft also blames Web sites that publish details about the flaw without giving it enough time to fix the problem: "It is unfortunate for customers that this issue was not reported to Microsoft, following responsible disclosure practices," the spokesperson said.

In December, Openwares.org, an open-source software development Web site, posted a patch designed to fix the Internet Explorer vulnerability, but Microsoft and industry analysts advised against installing it in case it clashed with future updates.

The administrator of Openwares.org, who requested anonymity, said that the patch has been downloaded more than 125,000 times and he has received numerous emails from people thanking him, including a group of Earthlink users: "There was a phishing scam targeted at Earthlink subscribers and I have had about 20 emails from Earthlink users who almost got ripped-off; our patch helped them," he said.

Microsoft said that when it completes its investigation, the fix will be included in the next batch of patches. However, if Microsoft believes the problem requires urgent attention, a patch will be issued outside its monthly cycle.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
107 out of 205 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

FINANCE / BANKING - C#.NET C#.NET C#.NET - 65K + 50% BONUS!!!

FINANCE & BANKING - ASSET MANAGEMENT - C#.Net C#.Net C#.Net C#.Net C#.Net One of Europes longest standing long/short Fund Managers is looking for a ...

Senior Technical Support Analyst 35-50k

The successful candidate will have experience of dealing directly with clients and will be responsible for investigation and resolution of client ...

Tester - Systems Integration - Financial Markets - Herts - c35k

You will also need the ability to execute automated test scripts through WinRunner or equivalent tools, use test harnesses for FIX messages and use ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment