All the latest UK technology news, reviews and analysis

Spoofing flaw hits major browsers

by Tom Sanders in California

24 Jun 2005

Be the first to comment

  • Tweet this

Security company Secunia has warned of a flaw in a number of browsers that could expose users to phishing attacks.

The company claims that most major browsers, including Internet Explorer, Firefox and Safari, suffer from a so-called Dialog Origin Spoofing Vulnerability.

Opera 8.01 is one of the few browsers not affected by the flaw.

A hacker could use a JavaScript dialog box to request a web visitor to enter confidential information. The flaw centres around the fact that users have no way of verifying the origin of the dialog box.

"The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open, for example a prompt dialog box, which appears to be from a trusted site," Secunia wrote in a security advisory on its website.

Hackers could exploit the flaw by offering a link to a trusted website that simultaneously provides a malicious pop up that asks for confidential information.

Microsoft has acknowledged the threat, but said that it will not release a patch because it uses a " current standard web browser functionality".

Instead the software vendor urged users to use common sense before entering confidential information through a web browser.

"If a particular window or dialog box does not have an address bar and does not have a lock icon that can be used to verify the site's certificate, the user is not provided with enough information on which to base a valid trust decision about the window or dialog box," said Microsoft.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Software Design Architect (Windows Database Application)

Software Design Architect (Windows Database Application...

Lead Java Developer - Mobile- Digital- Amsterdam

Lead Java Developer - Fast growing, young and international...

Graduate Software Support Engineer

Job Specification Graduate Support Engineer...

c# or asp.net Software Developer

Job Specification For: Software Developer...

To send to more than one email address, simply separate each address with a comma.