Latest Comments
"mihuleemyuta@hotmail.com"
by baran | Nov 21, 2008 2:53 AM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM
Web

Microsoft Internet Explorer XSS vulnerabilty could attract phishers

  • Email a Friend
  • Print Page
Microsoft Internet Explorer XSS vulnerabilty could attract phishers
By Dan Kaplan
Mar 16, 2007 6:29 AM
Tags: Microsoft | Internet | Explorer | XSS | vulnerabilty | could | provide | bite | for | phishers
Vulnerability tracking firm Secunia ranks the flaw, discovered by Israeli researcher Aviv Raff, as "less critical."

Attackers are able to inject script into the "Refresh the page" link that appears on a webpage when navigation to a particular site is cancelled.

Cyberthieves can then lead unsuspecting users to a phishing site.

"The victim will think that there was an error in the site or some kind of network error and will try to refresh the page," Raff said on his website.

"Once he will click on the "Refresh the page" link, the attacker’s provided content (e.g. fake login page) will be displayed and the victim will think that he’s within the trusted site because the address bar shows the trusted site’s URL."

Microsoft is investigating the "possible" vulnerability and was not aware of any customers being affected, a company spokesman told SCMagazine.com in an email.

Raff said the bug could be exploited to launch a phishing attack if the user wants to get to a banking, ecommerce or social networking site, for example. But the flaw likely cannot be taken advantage of to execute remote code, he added.

"To perform a phishing attack, an attacker can create a specially crafted navcancl.htm (which signals a canceled navigation) local resource link that will display fake content of a trusted site," Raff said.

Secunia said in an advisory today that users should only follow links from trusted sources and should not click on the "Refresh the page" link when located on a "Navigation Cancelled" page.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers