26 Oct 2006
Microsoft has issued a warning against a vulnerability in its Internet Explorer 7 browser that could allow attackers to spoof the address of a website.
An attacker could exploit the flaw by making a user click on a specially crafted website that would launch a pop-up window. The attacker could then forge the URL for the pop-up, for instance to make it look like a log-in window for an online bank. The URL of the phishing site will still be available, but is pushed outside the visible area of the window.
Danish security vendor Secunia published details of the vulnerability on its website on Wednesday. The company rated the vulnerability as "less critical", the second step on its five step security severity rating.
The flaw is the first published vulnerability in the Internet Explorer 7 browser that was launched last week. An IE7 vulnerability that Secunia published last week turned out to affect an Outlook component rather than Internet Explorer.
Microsoft in a blog posting noted that IE7's new anti phishing technology can help prevent the phishing pop-ups from opening. The company also noted that users should follow security best practices and refrain from entering confidential information on a website that doesn't offer an SSL certificate.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
ScheduALL, the global leader of Enterprise Resource Management...
My client is a well established, non profit organisation;...
PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...
HEAD OF DIGITAL - London - £80-95K + Excellent Bens...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
IE 7 Solution
Here is a solution.. Go and Get Firefox.
Posted by: benjamin cloutier 30 Oct 2006