Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 
Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™
  • HP PartnerONE | SolutionsINFINITE Visit us at hp.com/partners/us/go/4



  •  

    New IE Exploit Spoofs Web Sites

    in Channel News and Analysis


    Article Rating:starstarstarstarstar / 0
    Article Views: 1346

    Rate This Article:
    Add This Article To:
    Security researchers have uncovered a spoofing flaw in Internet Explorer that could allow a scammer to display a fake Web site with all the attributes of a genuine, secure site.

    Security researchers have uncovered a spoofing flaw in Internet Explorer that could turn out to be the perfect holiday gift for scammers.

    The bug, which has been confirmed on a fully patched Windows XP system with IE 6.0 and Service Pack 2, could allow a scammer to display a fake Web site with all the attributes of a genuine, secure site, including the URL and the icon indicating SSL security, according to researchers.

    Because the vulnerability is found in one of Internet Explorer's default ActiveX controls, scammers could use it to spoof the content of any site, researchers said. Users could be lured to the fake site via a link in an e-mail message, a tactic that continues to prove effective despite efforts to educate users.

    Resource Library:
    "Ordinarily, to spoof a site you have to have some issue on the Web site that you want to manipulate, which restricts what you can do," said Thomas Kristensen, chief technology officer at independent security firm Secunia, in a telephone interview. "Because this is embedded in IE by default, it's possible to inject content into any Web site. There's no way for a Web site to protect itself against this."

    There is currently no patch for the bug. Users can protect themselves by turning off ActiveX or switching the security level for the "Internet" zone to "high," researchers said.

    The vulnerability is caused by an error in the way the DHTML Edit ActiveX control handles certain inputs. The result is that a malicious site can execute script code in a user's browser session in the context of any other site, according to Secunia.

    Microsoft has issued a "critical" update to fix a flaw in SP2's Windows Firewall. Click here for the full story.

    Secunia has issued an advisory describing the issue and is offering an online demonstration to test browser vulnerability. The test displays a page with the URL "https://www.paypal.com/" and a padlock indicating a site with SSL security, but the content is supplied by Secunia.

    The bug was discovered by a researcher from Greyhats Security Group. Secunia's demonstration is based on a proof of concept from Greyhats.

    "Once it is displaying the site, if you follow best practices and look for the padlock, et cetera, you still won't have a clue [that the site is spoofed]," Kristensen said. "It isn't really even spoofing—you are really visiting the site, it's just that another site is controlling what you see."

    He said that SP2 targets more traditional vulnerabilities, such as buffer overflows, but it isn't as effective against flaws such as spoofing that can be used by scammers. Under a system with SP1 but without SP2, the flaw could be additionally used to disclose the content of local files, Secunia said.

    Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.



    Discuss New IE Exploit Spoofs Web Sites
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Channel News and Analysis Articles          >>> More By Matthew Broersma
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How to Unleash Application Performance with Solid-State Drives and Sun Servers
    Unleash the Beast! Learn from Sun and Intel experts how Sun servers equipped with Flash-enabled solid-state drives offer dramatic improvements to HPC, Web 2.0, and data center application performance Watch this video to learn more
    Watch Video
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Read Article