Language Selection

English French German Italian Portuguese Spanish

IE pop-up spoof won't get patch

Filed under
Microsoft

Microsoft does not plan to update Internet Explorer to prevent a spoofing attack that could trick users into giving out personal information to hackers.

In the attack, JavaScript is used to display a pop-up window in front of a trusted Web site. The pop-up appears to be part of the legitimate site, but actually is linked to a different, malicious site. A user might be fooled into sending personal information to the scammers.

Although the pop-ups could be used by attackers, overlaying multiple windows in a Web browser is a feature, not a vulnerability, according to an advisory posted Tuesday on Microsoft's TechNet Web site.

"This is an example of how current standard Web browser functionality could be used in phishing attempts," Microsoft said in the advisory.
Phishing is a prevalent type of online fraud that attempts to steal sensitive information such as usernames, passwords and credit card numbers. The schemes typically combine spam e-mail and fraudulent Web pages that look like legitimate sites.

Earlier this week, security monitoring company Secunia warned of the browser problem and rated it "less critical." The issue affects most major browsers, Secunia said.

The problem is that JavaScript dialog boxes do not display or include their origin. For an attack to occur, a user would have to visit a malicious Web site or click on a link before going to a trusted site, such as that of a bank. The attacker could then overlay part of the trusted site with a window asking for data such as a user name and password. Information entered would go to the attacker, instead of the bank.

Firefox developers at the Mozilla Foundation have been making moves to combat this kind of attack. In April, a patch was developed that allows people to block Java and Flash-based pop-ups unless they came from trusted sites.

Opera has said that its latest browser, 8.01, would display the pop-up's origin, letting a user inspect its URL to see if it came from a trusted site.

Source.

More in Tux Machines

FSF's High Priority Project List Now Has A Committee

The Free Software Foundation has now built up a committee to review their "High Priority Projects" list and they're looking for more feedback from the community. Nearly ten years ago is when the Free Software Foundation began listing what they viewed as the High Priority Free Software Projects in a list. This list has over time contained some definite high-priority projects related to freeing Java and Adobe PDF support and open graphics drivers to some more obscure projects of high priority like a free version of Oracle Forms, a replacement to OpenDWG libraries for CAD files, automatic transcription software, etc. I've personally called out many of the FSF HPP for what they're worth with my thoughts over the years. Read more

Latest Calibre eBook Reader and Converter Now Support Latest Kobo Firmware

The Calibre eBook reader, editor, and library management software has just reached version 2.13 and the developer has added an important driver and made quite a few fixes and improvements. Read more

Lubuntu 15.04 Alpha 1 Is Out and Still Uses LXDE – Gallery

Lubuntu 15.04 Alpha 1 (Vivid Vervet) has been officially released and it follows its Kubuntu and Ubuntu GNOME brethren. Users can now download and test this latest installment. Read more

Red Hat’s success aside, it’s hard to profit from free

Red Hat, which just reported a profit of $47.9 million (or 26 cents a share) on revenue of $456 million for its third quarter, has managed to pull off a tricky feat: It’s been able to make money off of free, well, open-source, software. (It’s profit for the year-ago quarter was $52 million.) Read more