A new vulnerability in the way Internet Explorer deals with Macromedia Flash files could leave users open to phishing attacks
Hackers could exploit an IE flaw to spoof the address bar in a browser window
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Phishers catch Internet Explorer again

Flash files a bit too flash, it seems

Matt Chapman, vnunet.com 05 Apr 2006
ADVERTISEMENT

A new vulnerability in the way Internet Explorer deals with Macromedia Flash files could leave users open to phishing attacks. 

The vulnerability was discovered by a user called Hai Nam Luke and posted on security firm Secunia's list of advisories

The problem is caused by a 'race condition' in the loading of web content and Macromedia .swf files in browser windows.

Malicious users could exploit this to spoof the address bar in a browser window that displays a Flash file from a malicious website. Secunia ranked the problem as 'moderately critical'.

"The impact of exploitation is reduced because the URL of the malicious Flash file is visible in the title of the browser window," said the security firm in a statement.

The vulnerability has been confirmed on a fully patched system running Internet Explorer 6.0 and Microsoft Windows XP with Service Pack 1 and 2.

Secunia said that other versions of the operating system and browser may also be affected.

See also:

EEye has engineered the patch to automatically remove itself when Microsoft's official patch comes throughWorkaround promises to protect browser in anticipation of official fix  28 Mar 2006
Two of the bugs could allow remote code to be run on the user's PCInternet Explorer problems may be fixed before the next update  27 Mar 2006
The malware opens a backdoor on the system and attempts to lower the security settingsZero day attack hits the web  24 Mar 2006
A newly discovered Internet Explorer bug could allow an attacker to take control of an affected systemMicrosoft admits three new vulnerabilities in as many days  23 Mar 2006
Attackers could exploit the OS X vulnerability to install spyware or rootkitsSoftware's blind faith in Zip files puts users at risk  22 Feb 2006

All Applications

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Business Analyst - £35,000 - £50,000 + benefits - Aylesbury    Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 396477 Environment Support Engineer Location - Reading Job Description: There is an initial requirement an Environment Support Engineer to provide support and maintenance for the development environments within ATLAS. This role encompases many ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
Swindon, Wiltshire, United Kingdom | EDS
EDS are currently looking to recruit a Change, Risk and Issue Analyst to join our Project Management Defence team in Swindon, Wiltshire. Summary: The Regional Operations Cell Analyst will work as part of a small ... more >
More job opportunities