On CBS MoneyWatch: Stop listening to Jim Cramer
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Oct 30, 2006 4:09:00 PM

Security researchers on Monday warned of a problem in Internet Explorer 7 that could allow malicious attackers to alter content in a legitimate Web site's pop-up window.

The browser issue could affect users who visit a trusted site by opening a pop-up window in that site that contains malicious code. This is the second IE 7 problem that has been discovered since Microsoft released the browser two weeks ago. Last week, a security flaw was discovered in IE 7 that could spoof the address of a pop-up window.

The two IE 7 security holes, if used in conjunction with each other, can easily dupe all but the most security-minded users, said Thomas Kristensen, chief technology officer of security company Secunia, which discovered the problems.

Secunia has classed the latest problem a security vulnerability, while Microsoft states the situation arises from "by-design behavior" in the browsers.

"The (Secunia) report describes a by-design behavior in popular Web browsers that allows a Web site to open or re-use a pop-up window," a Microsoft reprensentative said. "In Internet Explorer 7, the Web page's actual URL is displayed in a pop-up window address bar, enabling users to accurately make a trust decision."

Microsoft said that people who follow its safe browsing guidelines and verify an HTTPS connection before entering sensitive personal information can increase their ability to guard against an exploit.

Secunia rated the most recent flaw as "moderately critical" because viewing the content does not provide attackers access to a user's computer. But it can still prove harmful if a user enters sensitive information into the malicious pop-up window, such as credit card information, usernames or passwords, Kristensen noted.

The vulnerability is also rated moderately critical because it requires user interaction and affects only particular trusted Web sites.

Secunia noted that the security flaw can affect a fully patched system running IE 7 and Microsoft Windows XP Service Pack 2.

The security company advises users to avoid browsing untrusted sites while browsing sites that they trust.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 119 Talkback(s)
Popup in IE7 while in Firefox
I am not running IE7, but the crap is still on the system. When I
am using Firefox popups will appear that call up IE7 and display
the ads, etc... Popups are suppose to be blocked in both programs...any clues??? Thanks... (Read the rest)
Posted by: EdVincent Posted on: 02/20/07 You are currently: a Guest | | Terms of Use
use Firefox2.0  galileon | 10/30/06
This current flaw only catches IE7 up to ....  ShadeTree | 10/30/06
This flaw doesn't even work  georgeou | 10/30/06
The way that I understand it  Shelendrea | 10/30/06
Yeah you're right  georgeou | 10/30/06
maybe  Shelendrea | 10/30/06
Looks like this affects Firefox too  georgeou | 10/30/06
I will have to take a look at that  Shelendrea | 10/30/06
Popup in IE7 while in Firefox  EdVincent | 02/20/07
or you can...  WebThingy | 10/30/06
I totally agree!  Scrat | 10/31/06
Looks like FF 2.0 is doing even worse...  Qbt | 10/30/06
But FireFox will be patched long before IE7  dl@... | 10/30/06
Really?  Qbt | 10/30/06
Are you that big of a ****** dork?  nikoli | 10/30/06
LOL  Qbt | 10/30/06
You do realize  Shelendrea | 10/30/06
I never thought I would side with Peter on anything  slim-01 | 10/30/06
And this is what happens when  Scrat | 10/31/06
And what of you Scrat what is your cult?  Laff | 10/31/06
Of course...  jasonp@... | 10/31/06
Just.....  todbran@... | 10/30/06
not reliable  DarbyOhara | 10/30/06
It's just like with Windows...  nix_hed | 10/31/06
Are you spreading FUD?  Linux Geek | 10/30/06
It is classified as a flaw by ...  ShadeTree | 10/30/06
Never buy version zero....  bportlock | 10/30/06
But...  Qbt | 10/30/06
FireFox 2.0 is not nothig to write home about  Linux User 1 | 10/30/06
Any version of IE isn't up to any other Browser out there  slim-01 | 10/30/06
Huh?  Michael Kelly | 10/30/06
You could learn to read...  MacCanuck | 10/30/06
Neither is version 0.  ShadeTree | 10/30/06
He should have said point zero  Michael Kelly | 10/30/06
I disagree.  ShadeTree | 10/30/06
New features = new flaws  Michael Kelly | 10/30/06
WinXP an improvement over Win2k? No unless you count activation.  slim-01 | 10/30/06
Your personal bias aside ...  ShadeTree | 10/30/06
Re: WinXP an improvement over Win2k?  nix_hed | 10/31/06
Xp is more then a pretty UI bolted on W2K.  ShadeTree | 10/31/06
Shadetree besides Activation in XP it was too bulky  slim-01 | 10/31/06
Poor peterweter, no clue, and no facts..  Monkey_MCSE | 10/30/06
dang it...  Monkey_MCSE | 10/30/06
Currently not an issue  2max67 | 10/30/06
I look at it another way...but I do like to think different:)  Laff | 10/31/06
Another IE 7 pop-up security flaw discovered  Loverock Davidson | 10/30/06
Waxing poetic again Lovey?  Shelendrea | 10/30/06
Just plain and simple facts  Loverock Davidson | 10/30/06
Nice Try Lovey  Shelendrea | 10/30/06
I try and I succeed  Loverock Davidson | 10/30/06
No need to answer only because you are an idiot who can't.  slim-01 | 10/30/06
blah blah blah  Loverock Davidson | 10/30/06
Re: Loverock's BSD is the same as Linux  slim-01 | 10/30/06
I politely disagree.  Raymond Danner | 10/30/06
Vista Pricing  nix_hed | 10/31/06
Re:Re: Loverock's BSD is the same as Linux  mikeholli | 10/31/06
Extrapolating from there  tic swayback | 10/30/06
Ouch  Shelendrea | 10/30/06
No  Loverock Davidson | 10/30/06
Just trying to follow your logic  tic swayback | 10/30/06
Shouldn't be hard  Loverock Davidson | 10/30/06
Hey WinXP has been out for 5 years and MS still hasn't fixed it  slim-01 | 10/30/06
Every OS has had updates  Loverock Davidson | 10/30/06
Re: Loverock's every OS has updates  slim-01 | 10/30/06
Man, so now 2 weeks is a short time!  I am Gorby | 10/30/06
There you go using fuzzy logic again.  ShadeTree | 10/31/06
Sort of the same standard you hold GW Shrub, Cheeny, Rumsfield  Laff | 10/31/06
Once again off topic and wrong!  ShadeTree | 10/31/06
Believe me Shade I know GW Shrub is president and the election is over.  Laff | 10/31/06
Did you even read what I said.  ShadeTree | 10/31/06
Of course I read what you say....I find the way people's minds  Laff | 10/31/06
Microsoft source code blows !  Intellihence | 10/30/06
Another IE 7 pop-up security flaw discovered  Intellihence | 10/30/06
HAH!  cmndrnineveh@... | 10/30/06
Right  Loverock Davidson | 10/30/06
I believe  nix_hed | 10/31/06
IE 7 Trouble at it's worst  pat@... | 10/30/06
What?!  Leria | 10/30/06
See what I mean?  jasonp@... | 10/30/06
How to uninstall IE 7?  kbtank | 11/19/06
This could never be a problem...  jasonp@... | 10/30/06
a flaw's a flaw, no matter how you look at it.  nix_hed | 10/31/06
The Inconvenient Truth; Microsoft not a Web 2.0 firm  mighetto | 10/30/06
THE INCONVENIENT TRUTH - Mickey mouse Web 2  TonyMcS | 10/30/06
Crappy Movie References  nix_hed | 10/31/06
It may be  Shelendrea | 10/30/06
No guarantees  KWierso | 10/30/06
Didn't work for me  PB_z | 10/30/06
Did not work for me  georgeou | 10/30/06
Secunia being dishonest  PB_z | 10/30/06
You have to click on the "day in pictures"  georgeou | 10/30/06
I did click "day in pictures"  PB_z | 10/30/06
Get use to it... It's a MICROSUCKS product.  BeGoneFool | 10/30/06
Time for the meds BeGoneFool. (NT)  Scrat | 10/31/06
Will this mean  TheHonestTruth | 10/30/06
Nope, not for this issue.  Zeppo9191 | 10/30/06
Are you sure?  TheHonestTruth | 10/30/06
It depends on if they fix it before Vista ships  PB_z | 10/30/06
So the Vista will have a known flaw  TheHonestTruth | 10/31/06
IE7 security flaw  svga4864@... | 10/30/06
I don't think so  Leria | 10/30/06
Stop the BLAME GAME!!  mikeholli | 10/31/06
This will.......  todbran@... | 10/30/06
Ummm...  blarman_z | 10/30/06
firefox vs. IE game  humble99 | 10/30/06
lol, suke iy dic  not of this world | 10/30/06
Thats not the only problem  oscarwms | 10/30/06
this is rediculuos  inertman@... | 10/30/06
actually  ttocsmij | 10/30/06
oh drat  ttocsmij | 10/30/06
IE7 is unuseable  Jahbenzi | 10/31/06
Fed up with IE 7  vinsur001 | 11/02/06
Sounds like a hate session on Microsoft.  krismartin56 | 10/31/06
MSFT Is for Business not Home  brettze | 10/31/06
Yahoo and IE 7 don't mix OR unmix!  Eloheh | 10/31/06
Restore?  Eloheh | 10/31/06
help with IE7.0  hazeljean | 11/08/06
IE 7 does not allow drop downs to work  kbtank | 11/19/06
Major Defect in Shockwave Flash Object  jimdorval@... | 01/26/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here