On CBSSports.com: Come and get your daily Maxim Hotties!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Jun 23, 2005 11:35:00 PM

Microsoft does not plan to update Internet Explorer to prevent a spoofing attack that could trick users into giving out personal information to hackers.

In the attack, JavaScript is used to display a pop-up window in front of a trusted Web site. The pop-up appears to be part of the legitimate site, but actually is linked to a different, malicious site. A user might be fooled into sending personal information to the scammers.

Although the pop-ups could be used by attackers, overlaying multiple windows in a Web browser is a feature, not a vulnerability, according to an advisory posted Tuesday on Microsoft's TechNet Web site.

"This is an example of how current standard Web browser functionality could be used in phishing attempts," Microsoft said in the advisory.

Phishing is a prevalent type of online fraud that attempts to steal sensitive information such as usernames, passwords and credit card numbers. The schemes typically combine spam e-mail and fraudulent Web pages that look like legitimate sites.

Earlier this week, security monitoring company Secunia warned of the browser problem and rated it "less critical." The issue affects most major browsers, Secunia said.

The problem is that JavaScript dialog boxes do not display or include their origin. For an attack to occur, a user would have to visit a malicious Web site or click on a link before going to a trusted site, such as that of a bank. The attacker could then overlay part of the trusted site with a window asking for data such as a user name and password. Information entered would go to the attacker, instead of the bank.

Firefox developers at the Mozilla Foundation have been making moves to combat this kind of attack. In April, a patch was developed that allows people to block Java and Flash-based pop-ups unless they came from trusted sites.

Opera has said that its latest browser, 8.01, would display the pop-up's origin, letting a user inspect its URL to see if it came from a trusted site.

Graeme Wearden of ZDNet UK contributed to this report.

  • Talkback
  • Most Recent of 50 Talkback(s)
Possibly
but give the masses a ton a pop-up warnings and too many granular settings and you and I both know what the end result is......warnings turned off and settings set to the most functionality(least security).... (Read the rest)
Posted by: IT Scion Posted on: 06/28/05 You are currently: Logged In | Log out
IE pop-up spoof won't get patch Loverock Davidson   | 06/23/05
i'd lean more towards.. Monkey_MCSE   | 06/23/05
And so what should they do nhavar   | 06/23/05
Whatever they can DarthRidiculous   | 06/24/05
um... Protector   | 06/24/05
im an avid linux supporter... linuxoverwindows   | 06/24/05
There is no bug sepulcro   | 06/24/05
agreed linuxoverwindows   | 06/24/05
Glad you agree... Colonel_Panic   | 06/24/05
Bad Microsoft! Very bad!! eula-gree   | 06/24/05
I have 100% no problem with Internet Explorer Grayson Peddie   | 06/23/05
I don't either DarthRidiculous   | 06/24/05
I don't have a problem with IE either Otto_Delete   | 06/24/05
I have 100% problems with anything... Colonel_Panic   | 06/24/05
Just kidding, I use Mepis Linux, Firefox... Colonel_Panic   | 06/24/05
I don't have michael_t   | 06/24/05
Obviously you're not a Web developer then. Immanuel Tranz-Mischen   | 06/27/05
I'm with MS on this one rpmyers1   | 06/23/05
Not really IT Scion   | 06/23/05
Reply was to loverock...sry(nt) IT Scion   | 06/23/05
protecting users == limiting who can use linuxoverwindows   | 06/24/05
About the "JavaScript dialog boxes" ... PB_z   | 06/23/05
Actually.. d_jedi   | 06/23/05
The way I see it... thetargos   | 06/23/05
So don't click on a pop-up link! :-) HypnoToad   | 06/24/05
Reminds me of a really old programmer's ebrke   | 06/24/05
ok, tell me this... linuxoverwindows   | 06/24/05
that last post was meant for story not to your quote :) linuxoverwindows   | 06/24/05
The Door is open! Reverend MacFellow   | 06/24/05
This affect any Mac browser too sepulcro   | 06/24/05
The door is closed but the windows are OPEN (nt) michael_t   | 06/24/05
You could just lie trm1945   | 06/24/05
With due respect, I think you're missing the point... sfriedrich   | 06/24/05
Wow, And ZDNet Left Out The Most Important Quote Of The Article itanalyst   | 06/24/05
Way to expose the yellow journalism!... Colonel_Panic   | 06/24/05
read up dont just speak up MIS Master   | 06/24/05
Fundamental changes needed ... Ardian Daka   | 06/24/05
And when you are about to michael_t   | 06/24/05
If You're Not An AOL User Disregard itanalyst   | 06/24/05
Sure ... Ardian Daka   | 06/24/05
bridge sales Protector   | 06/24/05
Rats and... Colonel_Panic   | 06/24/05
Inhertance? Contact me: ben_dmeover@aol.com rick752   | 06/24/05
Figures...huge risk like this and... Colonel_Panic   | 06/24/05
Remarkable MS adherence to .... standards !!! michael_t   | 06/24/05
In fact IT Scion   | 06/24/05
Actually... Colonel_Panic   | 06/24/05
Possibly IT Scion   | 06/28/05
Why is it so michael_t   | 06/24/05
HAS ANYBODY NOTICED... Colonel_Panic   | 06/24/05

What do you think?

advertisement
advertisement
advertisement
Click Here