homenewsreviewstalkcompare pricestalk
NEW TODAY:
NEWS WEBSITE OF THE DAY - labs.ideeinc.com/multicolr                                                                           

Second flaw in IE7, claimes security firm Secunia

Microsoft has already responded to the news of a bug

NEWS: 26 October 2006 12:01 GMT by Amber Maitland

Danish security company Secunia has found its second flaw in IE7, to which Microsoft has responded swiftly.

The flaw lets hackers put a fake web address in a pop-up window, and could trick users into downloading from what looks like a secure website. The hacker can add special characters to the end of the web address so that only a part of the URL is displayed.

Microsoft's Christopher Budd has quickly posted an entry to the Security Response Center Blog, agreeing that there is an “issue with how URLs are displayed in the address bar. Specifically, we've seen that this occurs in a pop-up window after a user clicks a specially formed link on an untrusted website or in an untrusted email”.

He explains further: “Now, while the full URL is actually present in the address bar, the left part of the URL is not initially displayed. But, you can see the full URL if you either click in the browser window or in the address bar and then scroll within the address bar”.

The flaw is rated as “less critical” by Secunia, and Budd writes that Microsoft isn't aware of any attacks exploiting this flaw, but that the team is keeping an eye on it. He uses the rest of the entry to explain Microsoft's Anti-Phishing filter in IE7 and how it can protect against attacks exploiting flaws like the one Secunia has found.

>> Microsoft Security Response Center Blog - Latest entry


disable ad
Have Your Say
(Email address will not be published)


Second flaw in IE7, claimes security firm Secunia Image
Zoom/See more images

Tags


Latest in Software

NEWS WEBSITE OF THE DAY - labs.ideeinc.com/multicolr
NEWS Microsoft issues ActiveX flaw workaround
NEWS iPlayer to launch for Nokia N95
NEWS Half the population at risk to cyber crime
NEWS VIDEO OF THE DAY - OK Go

Latest on Pocket-lint.co.uk

NEWS WEBSITE OF THE DAY - labs.ideeinc.com/multicolr
NEWS VIDEO: Megawhat News - O2’s stock of the iPhone 3G runs out
NEWS O2 confirms iPhone 3G shortage
NEWS Daily news roundup - 08/07/08
NEWS Amphibious Tank brings you your beer




Top Stories

Sony releases fixed PS3 firmware version 2.41

NEWS
Sony Releases Fixed PS3 Firmware

Apologises for "inconvenience"

Google adds the word "privacy" to homepage

NEWS
Google Adds "Privacy" To Homepage

But removes another to keep the number the same

iPlayer to launch for Nokia N95

NEWS
iPlayer To Launch For N95

And embeddable clips to be made available



Came straight to this page? Visit Pocket-lint.co.uk for all the latest news and reviews.

disable ad

Broadband?

Compare 50+ deals available to you

Powered by Top 10 Broadband

Who's online

1411 guests, 1 member...

Newest reader

isivision

Pocket-lint.co.uk poll

Q. Should Microsoft just give up on Vista?

Vote YES?
Vote NO?

LAST TIME
When asked Is Blu-ray a waste of time? 50% said yes and 50% said no


disable ad
 

Also available on

news now logo google news logo news yahoo logo

All external sites will open in a new browser. Pocket-lint.co.uk does not endorse external sites. Copyright 2003 - 2008 Pocket-Lint Ltd.

Pocket-lint sites: www.pocket-lint.co.uk | www.photographypress.co.uk | www.gamesdog.co.uk | www.megawhat.tv
disable ad