You are here: silicon.com > Software > Security Strategy

Security Strategy

Phishing hole found in IE 7, says developer

What of Microsoft's built-in anti-phishing guards?

Tags: ie 7, phishing

By Joris Evers

Published: 15 March 2007 09:05 GMT

Microsoft is investigating a possible vulnerability in Internet Explorer 7 that could help cyber crooks launch phishing scams.

An attacker can use an error message displayed by the latest Microsoft browser to send web surfers to malicious sites that will display with the address of a trusted site, such as a bank, Aviv Raff, a developer in Israel, wrote on his website. Raff included an example where the error message directs the surfer to a site of his or her choice.

Microsoft is looking into the issue, a representative said. "Microsoft is not aware of any attacks attempting to use the reported vulnerability," the representative said in an emailed statement. "Microsoft will continue to investigate... to help provide additional guidance for customers as necessary."

The vulnerability relates to the message IE displays when web page loading is aborted, Raff wrote. An attacker can rig the message by creating a malicious link. The message will offer a link to retry loading the page; hitting it brings up the attacker's page but showing an arbitrary web address, he wrote.

To launch a phishing attack, an attacker can create a web link that purports to go to a trusted site, such as a bank. When clicked, the link results in a rigged error page. Following the reload link on that page will display the attacker's website with the address of the trusted site in the IE 7 address bar, Raff wrote.

IE 7 on Windows Vista and Windows XP are affected, Raff wrote.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Systems Engineer, Windows 2003 / Cisco / Linux / VMWare- Oxfordshire

We strive to reflect RMs core values by providing a great working environment, and our active sports & social team hosts a wide variety of events ...

Development Team Leader C# / ASP.NET / SharePoint Oxfordshire

We strive to reflect RMs core values by providing a great working environment, and our active sports & social team hosts a wide variety of events ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: