Help - Search - Members - Calendar
Full Version: New Internet Explorer Flaw URL Spoofing
Quest For More Glory forums > General > Hardware, Software, Tips and Tweaks
Spearflight
There is a new flaw in Internet Explorer.... actually, it's been known since February, but I just now read on it in Maximum PC.

Click

As long as you've been keeping up on your updates then you should be okay to go. smile.gif

If you notice something funky after clicking on it, mainly in the address bar, or in the left bottom corner when you hover, then you might want to either update your IE or make the switch to another browser.

This flaw allegedly affects Firebird 0.7 to some extent, but there will be something in the Address Bar to clue you in to something not being right. Firefox 0.8 is not affected at all. I don't know about Opera or Netscape, or plain vanilla Mozilla, but others could possibly check it I guess. wink.gif biggrin.gif
Archon-TiMe
everytihng seems normal (I'm using normal 1.6 mozilla) outside of the fact that it's bringing up ebay and not google as the site ...
Spearflight
That's the thing. It'll bring up Ebay as the site. But if you check on IE or something, hovering over the link I posted shows the destination as
CODE
http://www.google.com%01%00@ebay.com
then you're safe.

This is potentially dangerous, as a scammer can trick you into thinking you're logging into PayPal or something, but get your confidential information and whatnot.

If hovering over the link you see something like www.google.com%01%00@ebay.com then you know you're safe. Otherwise, get the latest build for your browser and hope that it's been fixed with them. smile.gif
Archon-TiMe
when i hover over it it shows www.google.com as the destination in the status bar on the bottom of the browser ... that's not good, right?
Spearflight
Nope. That means that someone could disguise their link as going somewhere you'd be secure giving personal information to, when in actuality you could be going somewhere completely different, like to a page served on their computer that will record sensitive data. You can read more on it here: Spoof
Archon-TiMe
Ok due to this i've eben playing around w/ different mozilla's. I tried firefox which I don't like but it does prevent this. Mozilla 1.6 the version i was using is vulnerable to this spoofing thing. But, Mozilla 1.7a the alpha release of 1.7 is not affected by the spoofing so that's what I"'m gonna stick w/
Maiandra
Thanks for the heads-up, Spear! smile.gif

*hugs her Firefox 0.8* wink.gif
Paladin Wizard
Double checks his autos. Yup, my IE updates automatically. So I'm fine. smile.gif bounce.gif
Spearflight
I hope IE fixed it by now. I mean, Microsoft is slow, but not THAT slow... right? wink.gif

But yeah, no problem to those who found the heads-up helpful. smile.gif
Paladin Wizard
Actually they had it fixed by the time you first posted this. smile.gif Microsoft is slowly getting better.
Spearflight
Yeah, I patched up the day after and found that it was working, but not everyone keeps up with their patching. People like me, for instance. biggrin.gif
Paladin Wizard
That's why they made an auto updater for IE. That's how I've obtained a few of them. But since I'm using 98 SE I only get IE updates now anyway. rolleyes.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.