Latest Comments
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM

Browser spoofing flaw discovered in Internet Explorer 7

  • Email a Friend
  • Print Page
Browser spoofing flaw discovered in Internet Explorer 7
By Dan Kaplan
Jul 17, 2007 9:38 AM
Tags: Browser | spoofing | flaw | discovered | in | Internet | Explorer | 7
The "less critical" flaw, according to tracking firm Secunia, is caused by an error in the processing of the "document.open()" method, used to open a new window and load documents as specified by a URL.

In the case of this vulnerability, users visiting a malicious website who try to navigate off the site – by manually entering a new URL – are brought to a compromised webpage hosted by the attacker even though the address bar shows them to be at the legitimate site they requested.

"Microsoft's (IE) seems to have a soft spot for browser entrapment vulnerabilities," discovering researcher Michal Zalewski said on the Full Disclosure mailing list.

"Just to recap, in these attacks, the user is made (to) believe he had left a webpage…but in reality, is prevented from doing so, and his browser continues to display content originating from the attacker."

In lieu of a patch, users are advised to close the windows of untrusted websites, according to today’s Secunia advisory.

The flaw, which requires JavaScript to run, was not tested in IE6, said Zalewski, who posted a demonstration of the attack.

Microsoft is investigating claims of the vulnerability and is not aware of any public exploits, a company spokesman told SCMagazine.com in an email.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers