IE7 phishing bug nets concern
Fishy
Posted in Enterprise Security, 19th March 2007 10:06 GMT
Free whitepaper – Extended Validation SSL Certificates
Security researchers have discovered a vulnerability in Internet Explorer 7.0 that might lend itself towards the creation of more convincing phishing attacks.
The cross-site scripting (XSS) bug creates a means to replace local page displaying a "Navigation to the webpage was canceled" message with a "Refresh the page" link. "This might be useful in a phishing attack, but it does sound rather complex and requires the user to jump through the hoops," the SANS Institute's Internet Storm Centre notes.
The flaw is perhaps more noteworthy for been among the first to affect IE 7 rather than the immediate threat it poses. Microsoft is investigating reports of the bug.
Meanwhile SANS has added the flaw to its list of unpatched Microsoft security vulnerabilities, as a secondary concern. The most pressing flaw remains a Word vulnerability that permits remote code execution, discovered in February. ®
Free whitepaper – Securing your Microsoft Internet Information Services (MS IIS) web server


The business case for application security
Reducing messaging and web security costs with managed services
Avoiding 7 common mistakes of IT security compliance
Server-gated cryptography
Airport insecurity: the case of lost laptops
Feds: Hospital hacker's 'massive' DDoS averted
Microsoft knew of nasty IE bug a year before attacks
BlockMaster SafeStick hardware-encrypted USB drive