Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Open source firm releases patch for IE spoofing flaw
The Age ^ | 18 December 2003 | Sam Varghese

Posted on 12/19/2003 6:04:04 AM PST by ShadowAce

An open source and freeware software development web site has released a patch to fix the URL spoofing vulnerability in Internet Explorer, which can be exploited by scammers who try to trick people into revealing details of online banking accounts or other private information.

Openwares.org, a Vaunatian company, with branches in Israel, the US and France, released the patch and the source code for the same a couple of days back.

The company has also set up two pages where users can test to see if they are vulnerable to the exploit, one a fake Microsoft Update example and the other an example of a fake PayPal site.

In its advisory, issued along with the patch, Openwares.org said: "Successful exploitation (of this flaw) allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address and status bars, which is different from the actual location of the page."

It gave the vulnerability a rating of 5 on a five-point scale.

While Microsoft has released an article providing details about the vulnerability, the company is yet to provide a patch.

The flaw was disclosed on December 9 by graphic designer Sam Greenhalgh.


TOPICS: Business/Economy; Culture/Society; Technical
KEYWORDS: computersecurity; ie; opensource; patch

1 posted on 12/19/2003 6:04:05 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; TechJunkYard; chance33_98; Calvinist_Dark_Lord; Dominic Harr; Bush2000; Nick Danger; ...
Tech Ping
2 posted on 12/19/2003 6:04:36 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Admin Moderator
Oops. I posted this without seeing the previous posting. Can you add the technical category to the first thread and delete this one, please?

Thank you.

3 posted on 12/19/2003 6:11:02 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
MICROSOFT refused to even acknowledge this FLAW for some days.

That makes me wonder --- was this a FLAW?


OR.....


An intentional feature to allow the governemnt to move someone (you?) to a specific website without your knowledge?


.
4 posted on 12/19/2003 6:26:08 AM PST by steplock (www.FOCUS.GOHOTSPRINGS.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: steplock
Better stock up on tinfoil for the holidays!
5 posted on 12/19/2003 6:29:33 AM PST by Moosilauke
[ Post Reply | Private Reply | To 4 | View Replies]

To: All
DO NOT install the Open Source patch! It introduces a buffer overflow vulnerability which is worse than the original problem.

A perfect example of jumping the gun, IMHO.

See the updated piece at The Register.

6 posted on 12/19/2003 7:40:15 AM PST by TechJunkYard
[ Post Reply | Private Reply | To 5 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson