On mySimon: Toys of the Year Award Winners
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jun 23, 2005 11:35:00 PM

Microsoft does not plan to update Internet Explorer to prevent a spoofing attack that could trick users into giving out personal information to hackers.

In the attack, JavaScript is used to display a pop-up window in front of a trusted Web site. The pop-up appears to be part of the legitimate site, but actually is linked to a different, malicious site. A user might be fooled into sending personal information to the scammers.

Although the pop-ups could be used by attackers, overlaying multiple windows in a Web browser is a feature, not a vulnerability, according to an advisory posted Tuesday on Microsoft's TechNet Web site.

"This is an example of how current standard Web browser functionality could be used in phishing attempts," Microsoft said in the advisory.

Phishing is a prevalent type of online fraud that attempts to steal sensitive information such as usernames, passwords and credit card numbers. The schemes typically combine spam e-mail and fraudulent Web pages that look like legitimate sites.

Earlier this week, security monitoring company Secunia warned of the browser problem and rated it "less critical." The issue affects most major browsers, Secunia said.

The problem is that JavaScript dialog boxes do not display or include their origin. For an attack to occur, a user would have to visit a malicious Web site or click on a link before going to a trusted site, such as that of a bank. The attacker could then overlay part of the trusted site with a window asking for data such as a user name and password. Information entered would go to the attacker, instead of the bank.

Firefox developers at the Mozilla Foundation have been making moves to combat this kind of attack. In April, a patch was developed that allows people to block Java and Flash-based pop-ups unless they came from trusted sites.

Opera has said that its latest browser, 8.01, would display the pop-up's origin, letting a user inspect its URL to see if it came from a trusted site.

Graeme Wearden of ZDNet UK contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 50 Talkback(s)
Possibly
but give the masses a ton a pop-up warnings and too many granular settings and you and I both know what the end result is......warnings turned off and settings set to the most functionality(least security).... (Read the rest)
Posted by: IT Scion Posted on: 06/28/05 You are currently: a Guest | | Terms of Use
IE pop-up spoof won't get patch  Loverock Davidson | 06/23/05
i'd lean more towards..  Monkey_MCSE | 06/23/05
And so what should they do  nhavar | 06/23/05
Whatever they can  DarthRidiculous | 06/24/05
um...  Protector | 06/24/05
im an avid linux supporter...  linuxoverwindows | 06/24/05
There is no bug  sepulcro | 06/24/05
agreed  linuxoverwindows | 06/24/05
Glad you agree...  Colonel_Panic | 06/24/05
Bad Microsoft! Very bad!!  eula-gree | 06/24/05
I have 100% no problem with Internet Explorer  Grayson Peddie | 06/23/05
I don't either  DarthRidiculous | 06/24/05
I don't have a problem with IE either  Otto_Delete | 06/24/05
I have 100% problems with anything...  Colonel_Panic | 06/24/05
Just kidding, I use Mepis Linux, Firefox...  Colonel_Panic | 06/24/05
I don't have  michael_t | 06/24/05
Obviously you're not a Web developer then.  Immanuel Tranz-Mischen | 06/27/05
I'm with MS on this one  rpmyers1 | 06/23/05
Not really  IT Scion | 06/23/05
Reply was to loverock...sry(nt)  IT Scion | 06/23/05
protecting users == limiting who can use  linuxoverwindows | 06/24/05
About the "JavaScript dialog boxes" ...  PB_z | 06/23/05
Actually..  d_jedi | 06/23/05
The way I see it...  thetargos | 06/23/05
So don't click on a pop-up link! happy  HypnoToad | 06/24/05
Reminds me of a really old programmer's  ebrke | 06/24/05
ok, tell me this...  linuxoverwindows | 06/24/05
that last post was meant for story not to your quote happy  linuxoverwindows | 06/24/05
The Door is open!  Reverend MacFellow | 06/24/05
This affect any Mac browser too  sepulcro | 06/24/05
The door is closed but the windows are OPEN (nt)  michael_t | 06/24/05
You could just lie  trm1945 | 06/24/05
With due respect, I think you're missing the point...  sfriedrich | 06/24/05
Wow, And ZDNet Left Out The Most Important Quote Of The Article  itanalyst | 06/24/05
Way to expose the yellow journalism!...  Colonel_Panic | 06/24/05
read up dont just speak up  MIS Master | 06/24/05
Fundamental changes needed ...  Ardian Daka | 06/24/05
And when you are about to  michael_t | 06/24/05
If You're Not An AOL User Disregard  itanalyst | 06/24/05
Sure ...  Ardian Daka | 06/24/05
bridge sales  Protector | 06/24/05
Rats and...  Colonel_Panic | 06/24/05
Inhertance? Contact me: ben_dmeover@aol.com  rick752 | 06/24/05
Figures...huge risk like this and...  Colonel_Panic | 06/24/05
Remarkable MS adherence to .... standards !!!  michael_t | 06/24/05
In fact  IT Scion | 06/24/05
Actually...  Colonel_Panic | 06/24/05
Possibly  IT Scion | 06/28/05
Why is it so  michael_t | 06/24/05
HAS ANYBODY NOTICED...  Colonel_Panic | 06/24/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here