New IE hole could perfect phishing scams
It allows attackers to create a fake Web site that looks like a genuine site
December 20, 2004 12:00 PM ETIDG News Service -
SAN FRANCISCO -- A newly reported security problem in Microsoft Corp.'s Internet Explorer Web browser allows attackers to create a fake Web site that looks exactly like a genuine site.
The vulnerability lets an attacker display any Web site while the address bar in Internet Explorer displays a trusted Web address -- https://www.paypal.com, for example -- and even shows the icon indicating that Secure Sockets Layer security technology is in use, security researchers warned on Thursday.
The flaw could result in more sophisticated phishing scams, which are online attacks that typically use spam e-mail messages with links to phony Web pages that look like legitimate e-commerce sites, where users are duped into revealing sensitive information such as passwords and credit card numbers.
The problem was discovered by a security researcher from the Greyhats Security Group and reported by Danish security company Secunia. The vulnerability lies in an ActiveX control in Internet Explorer and has been found to affect Version 6.0 of the browser running on Windows XP with Service Pack 2 and earlier versions, according to a Secunia advisory.
Microsoft is investigating the report, a company spokeswoman said Friday. "We have not been made aware of any attacks attempting to use the reported vulnerabilities or customer impact at this time, but we are aggressively investigating the public reports," she said.
Upon completion of this investigation, Microsoft may provide a fix as part of its monthly release of patch updates or as an out-of-cycle security update, she said. Meanwhile, Secunia suggests that users protect themselves by disabling ActiveX in Internet Explorer or setting the Internet Explorer security level to "high" for the Internet zone.
Banks are trying to combat phishing by educating their customers. For example, Citibank has a warning on its Web site that advises customers not to click on links in e-mail messages. Also, Citibank advises customers to manually enter the Web address for the bank in a Web browser to make sure they are dealing with Citibank and not a scammer.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Security
Additional Resources



White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

