Latest Comments
"mihuleemyuta@hotmail.com"
by baran | Nov 21, 2008 2:53 AM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

Secunia reports another Internet Explorer 7 flaw

  • Email a Friend
  • Print Page
By Ericka Chickowski
Oct 25, 2006 5:34 PM
Tags: Secunia | reports | another | Internet | Explorer | 7 | flaw
The vulnerability reporting firm said that an anonymous tip lead them to the vulnerability, which allows the browser to display a popup with a spoofed address bar that has special characters appended to the URL. The vulnerability makes it possible to only display a part of the address bar, which could potentially fool users into believing in the pop-up's credibility.


The hole is listed as a "less critical" vulnerability by Secunia, which has a demonstration of the vulnerability on its site.
According to Thomas Kristensen, Secunia CTO, it might be possible for the vigilant user to spot something that isn't quite right when a pop-up occurs, but he is worried about the danger to average users.
"This is the kind of spoofing vulnerabilities that (Microsoft) IE7 was supposed to be better at protecting against than its predecessor," said Kristensen. "Any user not wearing the paranoid glasses is easily fooled by this trick - despite the built-in anti-phishing mechanism being enabled."
Only in its first week since release, IE7 has already seen a pair of its vulnerabilities reported to the public. Just hours after the browser was first distributed, Secunia warned of an error in redirection handling for URLs with the mhtml: URI handler.
Click here to email Ericka Chickowski.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Access Control Whitepapers