PDA

View Full Version : Microsoft Confirms IE7 Address Bar Flaw


xpgeek
26-10-2006, 07:08 PM
Second flaw found in IE 7

Microsoft confirmed a vulnerability Thursday in the address bar of Internet Explorer 7. First reported by security firm Secunia on Wednesday, the issue occurs in popup windows. It is possible to display a somewhat spoofed address bar, the company said.

Due to this issue, a specially crafted URL with special characters may hide portions of the address. This could open the user up to attacks, including performing actions that it may not be aware of. Secunia has rated the issue as "less critical," its second lowest rating.

No attacks using this flaw are currently known, Microsoft said. It also recommended users make use of the Microsoft Phishing Filter that is included within IE7.

"The Microsoft Phishing Filter online service is designed to allow us to update it fairly quickly with information as sites are reported and confirmed by us," Christopher Budd of the Microsoft Security Response Center Blog said.

"We do have this issue under investigation and as always, once we complete our investigation we'll take appropriate steps to protect our customers," he continued.

However, Budd downplayed the flaw, saying Microsoft's research showed the full URL can still be displayed by clicking in the browser windows or address bar, or scrolling within the address bar.

Source (http://www.betanews.com/article/Microsoft_Confirms_IE7_Address_Bar_Flaw/1161879160)

Micron
30-10-2006, 03:12 PM
A vulnerability has been discovered in Internet Explorer 7, which can be exploited by malicious people to spoof the content of websites.

The problem is that a website can inject content into another site's window if the target name of the window is known. This can e.g. be exploited by a malicious website to spoof the content of a pop-up window opened on a trusted website.

Secunia has constructed a test, which can be used to check if your browser is affected by this issue:
http://secunia.com/multiple_browsers_window_injection_vulnerability_t est/

The vulnerability has been confirmed on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2.

Continued at Source... (http://secunia.com/advisories/22628/)

xpgeek
31-10-2006, 01:04 AM
So thats three now. Hmm, IE 7 is nice, but I still making damn sure my mother using Firefox.