All the latest UK technology news, reviews and analysis

New IE flaw allows easier phishing

by Robert Jaques

23 Dec 2003

Be the first to comment

  • Tweet this

Millions of Internet Explorer users have been warned of a security vulnerability within the browser that poses a "significant risk".

According to analysts from the X-Force division of security firm ISS, the flaw can allow website addresses or URLs to display incorrectly in the browser's navigation bar, thereby allowing scams that trick users into trusting a bogus website.

The flaw, which ISS says is trivial to exploit, may be triggered when individuals navigate to URLs from within emails or hostile web pages.

Similar vulnerabilities have been used extensively in mass emails, or fake websites designed to replicate the original in an effort to steal personal information from the victim.

"This type of attack has commonly been referred to as 'phishing'. Whereas past phishing attacks used URLs similar to the original, this new vulnerability allows URLs that are identical to the original website," said the X-Force Security Alert.

"This makes it almost impossible for individuals to differentiate between fraudulent sites and legitimate sites."

Affected versions of the browser include Internet Explorer 6.0, 5.5 and 5.01. The complete X-Force advisory can be viewed here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

1%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Helpdesk / Desktop Support Analyst (Windows 7, MAC, Windows Server 2008, LAN)

Helpdesk / Desktop Support Analyst (Windows 7, MAC, Windows...

Infrastructure / Server Support Analyst - 3rd Line, Windows 2008, Exchange 2010, VMware

Infrastructure / Server Support Analyst - 3rd Line, Windows...

Credit Risk Modeller, SAS, London, £50,000

Credit Risk Modeller, SAS, London, £50,000 Title- Credit...

Global Project/Programme Manager-with recruitment deployment experienc

My London client is looking for an experienced Programme...

To send to more than one email address, simply separate each address with a comma.