Spoofing bug found in IE 7

Written on October 26, 2006 – 3:50 am | by GoogleBot |

Security experts have found a weakness in Internet Explorer 7 that could help crooks mask phishing scams, the type of attack Microsoft designed the browser to thwart.

IE 7, released last week, allows a Web site to display a pop-up that can contain a spoofed Web address, security monitoring company Secunia said Wednesday. An attacker could exploit this weakness to trick people into believing they are on a trusted Web site when in fact they are viewing a malicious page, Secunia said in an alert.

“This makes it possible to only display a part of the address bar, which may trick users into performing certain unintended actions,” Secunia said. The company has created a demonstration that shows a Microsoft Web address in the pop up window, but displays content from Secunia.

The problem lies in the way Web addresses are displayed in the IE 7 address bar, a Microsoft representative said in an e-mailed statement. An attacker could exploit the issue by tricking a user to click on a specially formatted link, the representative said.

Full story: CNET News.com

Post a Comment

Comment spam protected by SpamBam

About this site

Welcome to Techbeta. Techbeta is a site focussed on tech news, and freeware/open source software for Windows, Mac OS X, Pocket PC and Linux. More

Want to subscribe?

 Subscribe in a reader Or, subscribe via email:
Enter your email address:  
Find entries :