
What of Microsoft's built-in anti-phishing guards?
By Joris Evers
Published: 15 March 2007 09:05 GMT
Microsoft is investigating a possible vulnerability in Internet Explorer 7 that could help cyber crooks launch phishing scams.
An attacker can use an error message displayed by the latest Microsoft browser to send web surfers to malicious sites that will display with the address of a trusted site, such as a bank, Aviv Raff, a developer in Israel, wrote on his website. Raff included an example where the error message directs the surfer to a site of his or her choice.
Microsoft is looking into the issue, a representative said. "Microsoft is not aware of any attacks attempting to use the reported vulnerability," the representative said in an emailed statement. "Microsoft will continue to investigate... to help provide additional guidance for customers as necessary."
The vulnerability relates to the message IE displays when web page loading is aborted, Raff wrote. An attacker can rig the message by creating a malicious link. The message will offer a link to retry loading the page; hitting it brings up the attacker's page but showing an arbitrary web address, he wrote.
To launch a phishing attack, an attacker can create a web link that purports to go to a trusted site, such as a bank. When clicked, the link results in a rigged error page. Following the reload link on that page will display the attacker's website with the address of the trusted site in the IE 7 address bar, Raff wrote.
IE 7 on Windows Vista and Windows XP are affected, Raff wrote.
Joris Evers writes for CNET News.com
Integration Architect/Manager Websphere MQ,WMQ,WMB, Message Broker Location: London Salary: 50,000 - 70,000 Company: ANSON MCCADE Job type: Permanent ...
WebSphere MQ Message Broker Consultants - UK Wide - ? Due to their continued grown, they are currently looking to recruit an experienced WebSphere MQ ...
This person will translate logical definition of contracts into physical XSD'sExperience on AIX v6 in terms of: Shell Scripting, Message Broker ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead
Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy