YOUR IT - Technology for you

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

Secunia claims another IE7 vulnerability

Your IT - Home IT

Danish security firm Secunia claims that another weakness has been discovered in Internet Explorer, which can be exploited by malicious people to conduct phishing attacks.

Last week, Secunia found an Outlook Express vulnerability that could exploit IE7 when users visited a malicious website.

Acording to Secunia, the latest problem involves a vulnerability which involves spoofing a URL in the address bar.

"The problem is that it's possible to display a popup with a somewhat spoofed address bar where a number of special characters have been appended to the URL. This makes it possible to only display a part of the address bar, which may trick users into performing certain unintended actions," the Secunia advisory reads.

Secunia has constructed a demonstration, which is available at the following address and says in its advisory that he weakness is confirmed in Internet Explorer 7 on a fully patched Windows XP SP2 system.

"These are the kind of spoofing vulnerabilities, which IE7 was supposed to be better at protecting against than its predecessor," said Secunia chief technology officer, Thomas Kristensen , in an email to iTWire.

"While the issue isn't clear cut since the vigilant (paranoid?) user might be able to spot that something isn't quite right, then any user not wearing the paranoid glasses is easily fooled by this trick - despite the built-in anti-phishing mechanism being enabled," Kristensen added.

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more