A new vulnerability in the way Internet Explorer deals with Macromedia Flash files could leave users open to phishing attacks
Hackers could exploit an IE flaw to spoof the address bar in a browser window
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Phishers catch Internet Explorer again

Flash files a bit too flash, it seems

Matt Chapman, vnunet.com 05 Apr 2006
ADVERTISEMENT

A new vulnerability in the way Internet Explorer deals with Macromedia Flash files could leave users open to phishing attacks. 

The vulnerability was discovered by a user called Hai Nam Luke and posted on security firm Secunia's list of advisories

The problem is caused by a 'race condition' in the loading of web content and Macromedia .swf files in browser windows.

Malicious users could exploit this to spoof the address bar in a browser window that displays a Flash file from a malicious website. Secunia ranked the problem as 'moderately critical'.

"The impact of exploitation is reduced because the URL of the malicious Flash file is visible in the title of the browser window," said the security firm in a statement.

The vulnerability has been confirmed on a fully patched system running Internet Explorer 6.0 and Microsoft Windows XP with Service Pack 1 and 2.

Secunia said that other versions of the operating system and browser may also be affected.

See also:

EEye has engineered the patch to automatically remove itself when Microsoft's official patch comes throughWorkaround promises to protect browser in anticipation of official fix  28 Mar 2006
Two of the bugs could allow remote code to be run on the user's PCInternet Explorer problems may be fixed before the next update  27 Mar 2006
The malware opens a backdoor on the system and attempts to lower the security settingsZero day attack hits the web  24 Mar 2006
A newly discovered Internet Explorer bug could allow an attacker to take control of an affected systemMicrosoft admits three new vulnerabilities in as many days  23 Mar 2006
Attackers could exploit the OS X vulnerability to install spyware or rootkitsSoftware's blind faith in Zip files puts users at risk  22 Feb 2006

All Applications

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Maidstone, United Kingdom | Kent Police
  Assistant Forensic Computer Analyst - Police Headquarters, Maidstone, £20,164 - £23,632 Permanent Contract Digital devices and information communication technology are present in almost every investigation the police service undertakes. Kent Police Digital Forensics Unit ... more >
Sutton, Surrey, United Kingdom | Royal Marsden Hospital NHS Trust
  The Royal Marsden NHS Foundation Trust is a centre of excellence for research, development, education and care in the treatment of cancer. Analyst Programmers, Band 6, £23,458-£31,779 plus 15% HCAS, Sutton, Surrey We are ... more >
London, United Kingdom | University of London (Institute of Education)
 INSTITUTE OF EDUCATION University of London Systems Administrator (London Knowledge Lab) Computing and Media Support Salary in the range £28,290 - £33,780 per annum, plus £2,323 London Allowance  Job share considered We are seeking to ... more >
London, United Kingdom | Tru-Est Ltd
Head of E-Commerce & IT, London, £35,000 - £40,000 + BonusMain Responsibilities - To identify, develop and improve the commercial opportunities for the company's existing online productsTo identify and develop new online opportunities and products ... more >
More job opportunities