On TechRepublic: 10 Firefox add-ons you gotta have
BNET Business Network:
BNET
TechRepublic
ZDNet

By Paul Festa
Posted on ZDNet News: Dec 10, 2003 10:53:00 PM

Microsoft on Tuesday said it was looking into reports of a potential bug in its Web browser that could help malicious hackers design convincing Web site spoofs.

The bug, according to security alerts by a bug hunter and a Danish security company, Secunia, could let hackers use a technique to display a false Web address on a fake site.

Secunia credited the bug to "Zap the Dingbat," who posted an alert to the Bugtraq security mailing list. That alert links to a demonstration of the exploit, and says Microsoft was informed of the bug Tuesday.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Malicious hackers frequently lure victims to convincing replicas of e-commerce sites such as eBay, where they're tricked into handing over financial and other private information. The method is said to be a key tool in credit card and identity theft.

Savvy Web surfers often figure out the ruse from irregularities in the Web address. But in the method described by Secunia, IE could allow the address bar for the spoofed eBay site, for example, to read "ebay.com."

"Microsoft is investigating new public reports of a possible vulnerability in Internet Explorer," the company said in a statement. "We have not been made aware of any active exploits of the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports."

Microsoft did not set a timetable for its investigation, but said it may eventually release a patch to address the problem. Meanwhile, the company recommended that people follow basic security procedures, including the use of firewalls, software updates and antivirus software.

Microsoft faulted security mavens for publicizing the flaw, implying that they hadn't given Microsoft sufficient time to craft a patch.

"Microsoft is concerned that this new report of a vulnerability in Internet Explorer was not disclosed responsibly, potentially putting computer users at risk," the statement reads. "We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality patches for security vulnerabilities with no exposure to malicious attackers while the patch is being developed."

Secunia was not immediately available for comment.

Secunia's advisory faulted IE for an "input validation error" that let a certain character sequence mask the actual Web address and substitute a fake one.

It recommended using a proxy server or firewall to filter the character sequence out of Web addresses, and urged people not to "follow links from untrusted sources."

  • Talkback
  • Most Recent of 77 Talkback(s)
New security patch is out, but not by Microsoft!
While the big boys at Redmond scratch their balls all day tring to come up with their next licensing scheme, an unknown outfit that goes by the name of Opensoft has released a security patch that fixe... (Read the rest)
Posted by: admin@startupmechanic.com Posted on: 12/17/03 You are currently: Logged In as: a Guest  | Login | Terms of Use
Use Mozilla or Firebird  richman555 | 12/10/03
Not just IE  jmeola75@... | 12/11/03
Other browsers do not have the vunerability  dragosani | 12/11/03
Re:Other browsers do not have the vunerability  middle of nowhere | 12/11/03
Plainly tell?  chrichton99 | 12/11/03
No, it isn't  Fred Fredrickson | 12/11/03
Please answer this:  chrichton99 | 12/12/03
ragardless...  ryusen | 12/12/03
Ummm...thatīs not the bug....!  Jomo_z | 12/11/03
Dang it!! Didin't they get the memo?  Jose Jimenez | 12/10/03
Make sure you get to real Viagra sites  FilledOut | 12/10/03
No, no, tell me it aint so, another negative artical about MS security.  DonnieBoy | 12/10/03
Like all the recent Linux security holes?  Loverock Davidson | 12/10/03
you mean holes like...  ryusen | 12/10/03
I'll bite  Richard Flude | 12/10/03
Richard Richard Richard  Squawkbox | 12/10/03
me2  Suicida| | 12/10/03
We are paying the idiots at Microsft, and they have billions of our money  DonnieBoy | 12/10/03
But you don't use Microsoft products  Loverock Davidson | 12/10/03
MS damage to non-MS users/developers  michael-t | 12/10/03
I do and dont  Suicida| | 12/10/03
So how are you paying for it?  NemesisNL | 12/14/03
Holee Software Batman!  0utasite | 12/10/03
Upgrade to Windows Server 2003  0utasite | 12/10/03
Certainitly wouldn't downgrade to Linux  Loverock Davidson | 12/10/03
Server 2003 isn't the answer, either  TechDiva_z | 12/10/03
On top of that...  in-DUH-vidual | 12/10/03
That's impossible.  NoB$ | 12/10/03
But why is that funny?  WhoIsDaMan | 12/10/03
Hate the new forums  WhoIsDaMan | 12/10/03
Only reasonable explanation?  Hug-Hes | 12/12/03
MS security is a joke.  Suicida| | 12/10/03
IE bug lets fake sites look real  Loverock Davidson | 12/10/03
yes, but only IE does this tot he address bar  ryusen | 12/10/03
You're right  doctormoriarty | 12/12/03
two points  ryusen | 12/10/03
The exploit didn't work for me when I tried it  toadlife | 12/10/03
The true cost of monopoly  Sunny Jalolly | 12/10/03
You mean you paid MS  FilledOut | 12/10/03
Overlooking a basic fact  master of illusion | 12/10/03
Most of the people here.....  Rick_K | 12/10/03
Darn!  Yen_z | 12/10/03
Only with dumb admins  Suicida| | 12/10/03
Exactly the customers MS wants  michael-t | 12/10/03
Hmm...here's an idea  jdane | 12/10/03
Sleeping in class  in-DUH-vidual | 12/10/03
You are right about Stats, wrong otherwise.  are-you-thinking | 12/10/03
better rethink...  stmueller | 12/11/03
IE Stinks  xero11 | 12/11/03
I agree, complacent  voska | 12/12/03
Not so simple...  Hug-Hes | 12/12/03
Not so complex either...  kevmit | 12/12/03
All My friends use Mozzila  voska | 12/11/03
Typical Argument  xero11 | 12/11/03
Cool article...  Jose Jimenez | 12/11/03
Imaginary Statistics are meaningless  Update victim | 12/11/03
Sorry about the formatting  Update victim | 12/11/03
don't kill your own argument,  ryusen | 12/11/03
Similar to  michael-t | 12/10/03
Wow, watching the holiday hate flow  FilledOut | 12/10/03
The Last Cumulative Patch for I.E.  The Real Bitch | 12/10/03
funny  Suicida| | 12/10/03
Help ???  Update victim | 12/11/03
Opera is immune  bmeacham98@... | 12/11/03
spoofs are as bad  JWatson77 | 12/11/03
Doesn't work on Mac OS X 10.2 on IE 5.2.2  ppflanz | 12/11/03
The problem is a business matter too  TTate | 12/11/03
How Do I Know?  BlackDiamond | 12/11/03
PayPal email spoofs will be lucrative now...  EJHonda | 12/11/03
Stop the madness  Jaded old guy | 12/11/03
IE Bug  dfyfe | 12/11/03
You Can't Protect Against being an IDIOT  Da_Bobcee | 12/11/03
Sure you can. It's called educating yourself. Try it.  kevmit | 12/12/03
It seems no trick for Mozilla  pesanti@... | 12/11/03
Look again  dscherf | 12/12/03
Outrageous!  paulgeaf | 12/15/03
New security patch is out, but not by Microsoft!  admin@... | 12/17/03

What do you think?

advertisement
advertisement

IP Networking

  • Anywhere, anytime productivity isn’t just for cyber-geeks and overachievers. It’s the state of business today, made possible through integrated wired and wireless networks, secure remote access, and advanced mobile applications and devices. Your users have what they need; do you?
  • From our sponsors
  • IT Solutions
  • AT&T IP Networking for your IT needs With AT&T IP Networking, you get flexible solutions designed specifically for your company’s IT needs Learn more
advertisement
Click Here