New IE Exploit Spoofs Web Sites

Martin

Deceased
New IE Exploit Spoofs Web Sites
By Matthew Broersma
December 17, 2004

Updated: Security researchers have uncovered a spoofing flaw in Internet Explorer that could allow a scammer to display a fake Web site with all of the attributes of a genuine, secure site.






Security researchers have uncovered a spoofing flaw in Internet Explorer that could turn out to be the perfect holiday gift for scammers. ADVERTISEMENT
The bug, which has been confirmed on a fully patched Windows XP system with IE 6.0 and Service Pack 2, could allow a scammer to display a fake Web site with all the attributes of a genuine, secure site, including the URL and the icon indicating SSL security, according to researchers.

Because the vulnerability is found in one of Internet Explorer's default ActiveX controls, scammers could use it to spoof the content of any site, researchers said. Users could be lured to the fake site via a link in an e-mail message, a tactic that continues to prove effective despite efforts to educate users.

http://www.eweek.com/article2/0,1759,1743443,00.asp
 

susie_q

Veteran Member
Thanks for the heads up, Martin. I have enough hassle with computers in my house, I don't need this one. ;)
 
Top