internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Few Browsers Safe from Latest Spoofing Flaw
Flaw Could Lead to Phishing Attacks
Sean Michael Kerner

Microsoft Internet Explorer isn't the only browser hit by a spoofing flaw that could be exploited by phishers. But it also won't be releasing a patch for it anytime soon.

According to Secunia Research, IE, Mozilla Firefox, Opera, and Apple Safari all have a similar "flaw" related to their use of JavaScript (define) dialog boxes.

"The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open, e.g. a prompt dialog box, which appears to be from a trusted site," a Secunia advisory states. A malicious site could potentially trick a user into disclosing personally identifiable information that could then be used for fraudulent purposes.

To further back its claim, Secunia has posted a proof-of-concept test of how the exploit works.

In a security advisory issued yesterday by Microsoft, the potential exploit was described as a potential issue relating to user confusion with the overlapping browser windows.

"Common to various browsers, including Internet Explorer, it is possible to have multiple, overlapping browser windows," Microsoft's advisory states. "An attacker could arrange windows in such a way as to trick users into thinking that an unidentified dialog or pop-up window is trustworthy when it is in fact fraudulent."

Microsoft does not plan on issuing a security update to address the dialog box threat.

"This is an example of how current standard Web browser functionality could be used in phishing attempts," the Microsoft advisory states.

As of press time no advisory on the issue had been posted on Mozilla's security site.

News courtesy of internetnews.com

June 22, 2005

Download Internet Explorer Now!Download

Download Mozilla Firefox Now!Download

View All Web Browsers

Contents:
1. Flaw Could Lead to Phishing Attacks




internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers