ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft denies spoofing is a security flaw

Dan Ilet ZDNet.co.uk

Published: 02 Nov 2004 14:44 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has denied that a spoofing technique available on its Internet Explorer browser is a security vulnerability.

The software giant accepted the possibility that spoofing could occur on version six of IE, but rejected claims that this was a security flaw.

In a prepared email statement from the company, a spokesperson said: "Microsoft is aware of a security issue reported last week that could allow spoofing the URL a user sees in Internet Explorer’s status bar. Users could see a URL in the status bar when the mouse hovers over the link on a webpage, but clicking the link would take the user to a different URL. Our investigation has indicated that this is not a security vulnerability."

Last week, a researcher in Germany, Benjamin Tobias Franz, posted warnings on bulletin board Web site Bugtraq, stating that Internet Explorer could spoof links if users put two URLs and a table inside an HTML href tag.

The result, Franz claimed, was that malformed links to URLs, could take users to an entirely different Web site without their knowledge.

This technique could be used for spoofing – a way of making users think they are visiting their chosen Web site when they are in fact looking at a 'spoofed' site.

Spoofing techniques are frequently used in phishing scams -- emails that attempt to steal user information by purporting to be from legitimate organisations. But Microsoft said that a large amount of social engineering would need to take place if victims were to fall for such attacks: "An attacker would need to entice a user to visit a site, and then entice the user to click a link on that site based on the URL that appears in the Internet Explorer’s status bar," said the statement. "Once on the destination site, the user would need to be enticed by the attacker to take some action, such as disclosing confidential financial information, without the user noticing that the URL in the address bar does not match the URL that the user thought he [or] she was visiting."

The company advised users to check that the URL in the browser address bar was the intended destination before going to the site. Franz and Microsoft agreed that Windows XP SP2 is unaffected by the issue.

Microsoft added: "[We] will evaluate the feasibility of implementing similar changes on earlier versions of Windows in the future."

On the Bugtraq Web site, Franz said that HTML email messages were vulnerable to the technique, so Microsoft Outlook Express was also affected. Franz wrote that users should avoid non-trusted links, or right-click on links to see the real target.

According to security firm NetCraft, Mozilla Firefox users are not affected by the issue.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
167 out of 273 people found this useful


Full Talkback thread

1 comment

  1. Eudora has just put in a new feature. When you ho... Howard Mirkin

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Service Desk Analyst @ top Hedge Fund! (ITIL,MS Office/Outlook)

Knowledge of Help Desk systems such as Touchpaper, Remedy AR System, Digital Workplace or Peregrine system would be beneficial, as would Microsoft ...

IT Support/ Windows 2000/ XP/ Server2003/ AD/OFFCIE/ Outlook/KENT/25k

IT Desktop Support/ Windows 2000/ XP/ Server 2003/ Active Directory/ / Exchange/ OFFCIE/ Outlook Are you looking to further your career. Globally ...

Desktop Support/SE.London/ KENT/ XP/ AD/ Exchange/ Outlook/ 25k + Bens

Desktop Support/ Office/ XP/Outlook/ KENT/Active Directory/ MCP/Blackberry/ Exchange/ 25k UKs leading travel organisation are looking for a Desktop ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation