Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Toolbar community reports Internet Explorer address bar spoofing vulnerabilities actively exploited
Netcraft ^ | Jan. 17, 2005 | Netcraft

Posted on 01/17/2005 10:43:37 AM PST by holymoly

A number of recent phishing sites blocked by the Netcraft Toolbar community have had a common technique of using JavaScript to create a narrow popup window, which is then placed on top of the Address bar. A fake URL is entered into the popup, using the same default font as the real address bar. The script continually checks the location of the browser window and moves the popup accordingly, ensuring that it is always placed on top of the Address bar, thus obscuring the real URL of the phishing site.

Look!

The image above illustrates a live phishing site in action. In this case, the content looks genuine, as the URL appears to belong to the PayPal web site, https://www.paypal.com/cgi-bin/webscr?cmd=_login-run, but the content is really being served from a phishing site at http://quith.info/paypal/index.html. The only clue that something is wrong is that the browser is not displaying the padlock in the bottom right hand corner, indicating that this is not really a secure web page. A bug in the script also causes the popup window to remain visible even when the browser is minimized.

Toolbar

However, the Toolbar reveals the true location of the web site, which is hosted in Poland. People using the toolbar are then able to report the site, and thereby block access to the page for other less alert people using the Toolbar.

Similar attacks against institutions including PayPal, eBay, TCF Bank, Regions, GarantiBank and LloydsTSB, have been reported and blocked by the Toolbar community in the last few days. In all cases, nearly-identical scripts have been used, suggesting either that the same fraudsters are responsible for all of the attacks, or perhaps simply that fraudsters are copying ideas from each other.

This can affect all versions of Internet Explorer on Windows XP although the popup window does not correctly obscure the real URL if Service Pack 2 is installed.

The Netcraft Toolbar is currently available for Internet Explorer, and automatically blocks access to known phishing sites whilst displaying the longevity, hosting location and country for each site you visit. The toolbar can be freely downloaded.


TOPICS: News/Current Events
KEYWORDS: address; bho; browser; computersecurity; exploit; explorer; ie; internet; java; javascript; microsoft; msie; phishing; security; spyware; toobar; toolbar; url; windows
Navigation: use the links below to view more comments.
first 1-2021-35 next last
Heads up for IE users (aka "IE victims").
1 posted on 01/17/2005 10:43:50 AM PST by holymoly
[ Post Reply | Private Reply | View Replies]

To: holymoly

Using Mozilla "Firefox" currently. I rarely use IE anymore....and my browser is Win98. I tried XP, thought it was garbage and reloaded 98. Been happy as a clam ever since.


2 posted on 01/17/2005 10:48:09 AM PST by Bombardier (Jihad, Nazism....Umma, Deutsches Reich.....no diff.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Thank goodness for firefox.


3 posted on 01/17/2005 10:49:16 AM PST by flashbunny (Every thought that enters my head requires its own vanity thread.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly
That should actually read:

Heads up for IE users
4 posted on 01/17/2005 10:50:08 AM PST by crail (Better lives have been lost on the gallows than have ever been enshrined in the halls of palaces.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: crail

Thanks for fixing that. ;)


5 posted on 01/17/2005 10:51:12 AM PST by holymoly (About:Blank)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Bombardier
Using Mozilla "Firefox" currently. I rarely use IE anymore....and my browser is Win98. I tried XP, thought it was garbage and reloaded 98. Been happy as a clam ever since.

Using Firefox as well but as far as rating XP as an OS; Its far superior to windows 98. Why you would sit on an old 95 kernel rather than the NT architecture is beyond me.

To me, it would be like buying a 1994 Firebird instead of a 2005 Mustang. Just doesnt make sense. Plus, 98 is far less secure than XP so im not sure what you are gaining.

6 posted on 01/17/2005 10:54:39 AM PST by smith288 (I have posted over 10,000 times. The more I post, the more intelligent you become!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: smith288

I have two swappable drives on my pc. I used to run windows ME (one of the worst things ever) all the time but needed XP pro for a few apps.

XP still doesn't work with my flash card reader and doesn't want to play nice on my network, no matter what I try. At the same time after years of using ME I have everything tweaked to where it's extremely reliable and pretty fast. Every time I swap in the XP drive it's more annoying than impressive.

The only thing MS has going for it is the availability of apps. If I could get all the applications I need to run on linux, I would be there in a heartbeat.


7 posted on 01/17/2005 11:01:10 AM PST by flashbunny (Every thought that enters my head requires its own vanity thread.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: holymoly

Why does anyone use ANY Windows garbage?

Using a Mac since 1985. Virus, pop-up, spyware, "phishware" free!


8 posted on 01/17/2005 11:02:03 AM PST by Wacka
[ Post Reply | Private Reply | To 1 | View Replies]

To: smith288
Plus, 98 is far less secure than XP so im not sure what you are gaining.

XP requires a lot more horespower for acceptable performance than does 98. Could be XP ran like a lazy dog on their PC

9 posted on 01/17/2005 11:02:41 AM PST by rogers21774
[ Post Reply | Private Reply | To 6 | View Replies]

To: Wacka
Why does anyone use ANY Windows garbage?

Well, in my case, because my R/C Flight Simulator software requires it. That's the only reason I ever boot MS anymore.

10 posted on 01/17/2005 11:04:39 AM PST by steve86
[ Post Reply | Private Reply | To 8 | View Replies]

To: smith288
To me, it's like buying a 1994 Firebird insead of a 2005 Mustang when the guy down the road is giving away Ferraris for free.

But that's just me... I'll never turn back.
11 posted on 01/17/2005 11:04:40 AM PST by crail (Better lives have been lost on the gallows than have ever been enshrined in the halls of palaces.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: smith288
Using Firefox as well but as far as rating XP as an OS;It's far superior to windows 98. Why you would sit on an old 95 kernel rather than the NT architecture is beyond me.

Mostly because I'm using a six-year old computer with a P2 processor. I had to swap out my harddrive a couple years back, and added some additional RAM to my motherboard. At the suggestion of my manufacturer, I installed XP on the new harddrive, but it turned out to be incompatible with the rest of my hardware. So, I overwrote the HD with zeros, did a FAT32 partition, and then formatted and installed Win98 again.

The only problems I had recently with my IE was that some popup blocker software my ISP provided kept crashing my browser, so I shut that software off, resumed using Yahoo popup blocker, and then installed Firefox. I rarely use IE anymore, and Firefox doesn't crash like IE does. In fact, since I installed Firefox, I have less spyware on my machine, haven't seen the Blue Screen of Death, and can actually go to WorldNet Daily without my screen freezing from all the popups. Like I said, happy as a clam.

12 posted on 01/17/2005 11:04:41 AM PST by Bombardier (Jihad, Nazism....Umma, Deutsches Reich.....no diff.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Wacka; Bush2000; Swordmaker

Who's going to ping Bush 2000 to this thread?


13 posted on 01/17/2005 11:05:28 AM PST by IncPen (Beware the fury of a patient man.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: smith288

I agree. Windows 98 is extremely insecure... not to mention poor memory management, BSOD, etc... XP Pro SP2 is the way to go. :) ( I am sure the open source people with have something to say as well)

-dubie, MCP, CSSA


14 posted on 01/17/2005 11:06:50 AM PST by dubie
[ Post Reply | Private Reply | To 6 | View Replies]

To: holymoly

I've got the same thing going on with a "ysearchus" hidden presence. I've been trying to discover how to get rid of them.


15 posted on 01/17/2005 11:09:54 AM PST by blackdog (Demorat Politician = Those in power who manipulate tribal hatreds for personal gain.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bombardier
I recently order a FireFox CD and instruction manual. I've heard that FireFox cures a lot of problems and hope that it's true.

I don't have xp and am still using the original version of Windows 98. I have some problems with 98 and primarily when exiting WordPerfect. Frequently, after having exited WP, I lose control of the cursor. I've reloaded 98 and WP and still have the same problem.

16 posted on 01/17/2005 11:10:47 AM PST by davisfh
[ Post Reply | Private Reply | To 2 | View Replies]

To: IncPen
Who's going to ping Bush 2000 to this thread?

You. I guess. :-)

17 posted on 01/17/2005 11:12:20 AM PST by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: blackdog
I've got the same thing going on with a "ysearchus" hidden presence. I've been trying to discover how to get rid of them.

Have you tried Ad-Aware SE and/or Spybot - Search & Destroy? (If not, see my FR homepage for links).

If those fail to help, you may need to visit SpywareWarrior.com (in particular their forum, for expert help).
18 posted on 01/17/2005 11:13:51 AM PST by holymoly (About:Blank)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Bombardier
Mostly because I'm using a six-year old computer with a P2 processor.

That is a legitimate reason though I would recommend, if you are using just for browsing and word processing, to use a Linux distro. They are quite secure and can perform as well on a lower end machine than XP can on a high end machine.

19 posted on 01/17/2005 11:15:28 AM PST by smith288 (I have posted over 10,000 times. The more I post, the more intelligent you become!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: flashbunny
XP still doesn't work with my flash card reader and doesn't want to play nice on my network, no matter what I try

XP doesn't natively load netbeui, did you load the IPX/SPX/netbios protocol on XP? You'll find it will see your 95/98/ME machines thereafter. As for flash card readers, most don't require a driver with XP so I'm sort of suprised. What brand is it?

20 posted on 01/17/2005 11:15:43 AM PST by Malsua
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson