« The Big Credit Card Theft | Main | New Spoof Affects IE and Firefox »

June 22, 2005

Dialog Origin Spoofing Vulnerability

Lockergnome's Tech News Watchhttp://channels.lockergnome.com/news [Lockergnome's Tech News Watch] Secunia Research has discovered this security vulnerability in several web browsers, including Safari and Internet Explorer on Mac. The vulnerability “…can be exploited by malicious web sites to spoof dialog boxes.

Some slightly related from Technorati and Google.

Speed of Thought...http://homepage.mac.com/sbooneaz/iblog [Speed of Thought...] Web Browser Spoofing Flaw found...: The vulnerability, confirmed on fully patched versions of Microsoft Corp.'s dominant Internet Explorer browser, can be exploited by malicious hackers to trick surfers into disclosing confidential information, including credit card and social security numbers.

Aviran's Placehttp://www.aviransplace.com [Aviran's Place] New Spoof Affects IE and Firefox: Research has discovered a vulnerability in various browsers, which can be exploited by malicious web sites to spoof dialog boxes. The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g.

Msmvps.com[Msmvps.com] Internet Explorer for Mac Dialog Spoofing Vulnerability: A vulnerability has been discovered in Internet Explorer for Mac, which can be exploited by malicious web sites to spoof dialog boxes.

Blogs.msdn.com[Blogs.msdn.com] Aaron Margosis' WebLog :: If you click on the circle or the group name, PrivBar will display a dialog like the one below showing you detailed information about the current token, including its principal (the user account), logon ID, whether you are running with a restricted token, groups, restricted SIDs (if a restricted token), and privileges. The information that appears in the dialog is collected in a background thread so as not to slow down IE/Explorer startup.

Kayodeok.co.uk[Kayodeok.co.uk] Kayode Okeyode's Weblog: My computer quickly became contaminated with the most spyware programs I have ever received in a single sitting, including at least the following 31 programs: 180solutions, Addictive Technologies, AdMilli, BargainBuddy, begin2search, BookedSpace, BullsEye, CoolWebSearch, DealHelper, DyFuca, EliteBar, Elitum, Ezula, Favoriteman, HotSearchBar, I-Lookup, Instafin, Internet Optimizer, ISTbar, Megasearch, PowerScan, ShopAtHome Select, SearchRelevancy, SideFind, TargetSavers, TrafficHog, TV Media, WebRebates, WindUpdates, Winpup32, and VX2 (DirectRevenue). (Most product names are as detected by Lavasoft Ad-Aware.) All told, the infection added 58 folders, 786 files, and an incredible 11,915 registry entries to my test computer.

Myitforum.techtarget.comhttp://myitforum.techtarget.com [Myitforum.techtarget.com] Opera Download Dialog Spoofing Vulnerability: Secunia Research has discovered a vulnerability in Opera, which can be exploited by malicious people to trick users into executing malicious files.

http://operawatch.blogspot.com [Operawatch.blogspot.com] Opera Watch: The Unofficial Opera Blog: October 2004: And often, these inexperienced web page writers take advantage of IE’s tolerance on malformed html by testing it just in IE. And to make matters even worse, since IE renders malformed html and while most other browsers would ignore the problem html, some web developers are led to believe that IE has better support for html.

Reflected tags on Technorati: Blog, ,

Posted at June 22, 2005 12:33 PM

Comments

Post a comment

Thanks for signing in, . Now you can comment. (sign out)

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)


Remember me?