Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Internet Explorer URL Spoofing Vulnerability
Secuina ^ | 12/09/03 | Zap The Dingbat

Posted on 12/11/2003 10:32:57 AM PST by Salo

Internet Explorer URL Spoofing Vulnerability

Secunia Advisory: SA10395 Release Date: 2003-12-09 Last Update: 2003-12-11

Critical: Moderately critical Impact: ID Spoofing

Where: From remote

Software: Microsoft Internet Explorer 6

Description: A vulnerability has been identified in Internet Explorer, which can be exploited by malicious people to display a fake URL in the address and status bars.

The vulnerability is caused due to an input validation error, which can be exploited by including the "%01" and "%00" URL encoded representations after the username and right before the "@" character in an URL.

Successful exploitation allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address and status bars, which is different from the actual location of the page.

This can be exploited to trick users into divulging sensitive information or download and execute malware on their systems, because they trust the faked domain in the two bars.

Example displaying only "http://www.trusted_site.com" in the two bars when the real domain is "malicious_site.com": http://www.trusted_site.com%01%00@malicious_site.com/malicious.html

A test is available at: http://www.secunia.com/internet_explorer_address_bar_spoofing_test/

The vulnerability has been confirmed in version 6.0. However, prior versions may also be affected.

Solution: Filter malicious characters and character sequences in a proxy server or firewall with URL filtering capabilities.

Don't follow links from untrusted sources.

Reported by / credits: Originally discovered by: Zap The Dingbat

Status bar variant reported by: Chris Hall

Changelog: 2003-12-11: Linked to test. Added information regarding variant, which makes it possible to spoof URL in the status bar as well.


TOPICS: Business/Economy; Crime/Corruption; Technical
KEYWORDS: computersecurity; explorer; lowqualitycrap; microsoft; security; windows
Navigation: use the links below to view more comments.
first 1-2021-4041-58 next last
This one's a Doozy. Be very careful, Freepers.
1 posted on 12/11/2003 10:33:00 AM PST by Salo
[ Post Reply | Private Reply | View Replies]

To: rdb3; Bush2000; ShadowAce; Ernest_at_the_Beach
Technical Ping.
2 posted on 12/11/2003 10:33:48 AM PST by Salo (Hold my beer and watch this!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CheneyChick
The Mac version of IE is not affected. For Windows, the Mozilla variants are ok.
3 posted on 12/11/2003 10:34:55 AM PST by Salo (Hold my beer and watch this!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: EdReform
BTTT
4 posted on 12/11/2003 10:37:39 AM PST by EdReform (Support Free Republic - Become a Monthly Donor)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
http://www.uva.edu Cool!!
5 posted on 12/11/2003 10:39:20 AM PST by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
hmmm - may have to go back to netscrape.
6 posted on 12/11/2003 10:45:08 AM PST by flashbunny
[ Post Reply | Private Reply | To 3 | View Replies]

To: Salo

Yup, this is a big one.

Expect vast volumes of porn links to be disguised in this manner very soon.

7 posted on 12/11/2003 10:45:20 AM PST by Malsua
[ Post Reply | Private Reply | To 1 | View Replies]

To: Malsua
Porn links are merely offensive. Think of a fake MS Patching site, or fake financial institutions. You could wreak havok with trojans or could steal identities with ease - and the redirect is trivial.

And did I mention no patch in Dec?
8 posted on 12/11/2003 10:48:36 AM PST by Salo (Hold my beer and watch this!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: AppyPappy
You're evil. I like it! :-)
9 posted on 12/11/2003 10:49:36 AM PST by Salo (Hold my beer and watch this!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Salo


>>Porn links are merely offensive. Think of a fake MS Patching site, or fake financial institutions. You could wreak havok with trojans or could steal identities with ease - and the redirect is trivial. <<

Agreed, except there will certainly be porn links which disquised will lead to sites where malicious scripts can run. The financial and banking bits are indeed disturbing.

Like.. "click here to go to paypal" And it takes you to a paypal login page at Paypal.com but it's not paypal. It's scumbag.com.

Glad i'm doing most of my browsing in firebird these days.

10 posted on 12/11/2003 11:17:41 AM PST by Malsua
[ Post Reply | Private Reply | To 8 | View Replies]

To: Salo
pretty easy too...now as to how they did that FQDN change...must be some additional scripting required.

Welcome to Cornell University!

11 posted on 12/11/2003 11:27:27 AM PST by Malsua
[ Post Reply | Private Reply | To 9 | View Replies]

To: Salo
Has anybody validated that this is true?
12 posted on 12/11/2003 11:29:48 AM PST by sd-joe
[ Post Reply | Private Reply | To 1 | View Replies]

To: Malsua
Awesome! http://www.dnc.org <-- Visit the DNC platform!
13 posted on 12/11/2003 11:33:42 AM PST by smith288 ("The United States has a system of taxation by confession." - Hugo Black,Supreme Court Justice)
[ Post Reply | Private Reply | To 11 | View Replies]

To: sd-joe
Has anybody validated that this is true?

I dont know...go here for more info http://www.mcAfee.com

14 posted on 12/11/2003 11:36:45 AM PST by smith288 ("The United States has a system of taxation by confession." - Hugo Black,Supreme Court Justice)
[ Post Reply | Private Reply | To 12 | View Replies]

To: sd-joe
Look at the replies here. We are doing it.
15 posted on 12/11/2003 11:37:18 AM PST by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: smith288
OOOPS!

Awesome! http://www.dnc.org <-- Visit the DNC platform!

16 posted on 12/11/2003 11:39:25 AM PST by smith288 ("The United States has a system of taxation by confession." - Hugo Black,Supreme Court Justice)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Salo
Use Opera - not affected.
17 posted on 12/11/2003 11:40:25 AM PST by 4CJ ('Scots vie 4 tavern juices' - anagram by paulklenk, 22 Nov 2003)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
And to think this was the month in which Microsoft said it wouldn't be releasing any patches. They just accidentally released one for an older bug, and now they're going to have to release one for this.

It's really sad that it's big news when Microsoft says it's going to go just one month without having to patch their OS, but then they have to anyway.

Luckily my main browser is Mozilla even when I'm on Windows.

18 posted on 12/11/2003 11:43:52 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
Of the browsers I have on my system:

IE 4 failed
Netscape 4.7 passed
Netscape 7.01 passed

(I only use IE to check cross-browser compatibility in my HTML.)
19 posted on 12/11/2003 11:47:30 AM PST by Never_take_me_seriously
[ Post Reply | Private Reply | To 1 | View Replies]

To: antiRepublicrat
Alas, that puts you in a very small minority. What % does IE have? Like in the 80s or something? I use it here at work, but at home I use Safari.
20 posted on 12/11/2003 11:53:15 AM PST by Salo (Hold my beer and watch this!)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-58 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson