Slashdot Mirror


New IE Bug Hides Real Site Address

Norman at Davis writes "ZDNet is running a story on a new security flaw in Microsoft's Internet Explorer which could let hackers use a technique to display a false Web address on a fake site according to an advisory from the Danish security company Secunia. The Danes report that 'the vulnerability is caused due to an input validation error, which can be exploited by including the "%01" URL encoded representation after the username and right before the "@" character in an URL.' PC World reports that 'Microsoft says it is investigating reports of the vulnerability. When that inquiry is complete, the company will take whatever steps it deems necessary, such as issuing a new patch, a spokesperson says.' And for good measure, here's what Google news is covering on it right now."

31 of 683 comments (clear)

  1. Re:This bodes ill by glpierce · · Score: 5, Funny

    ...and Slashdot, where there are so many people trying to get you to look at goatse

    --
    G
  2. See also by lamery · · Score: 5, Funny

    http://www.microsoft.com/ie_advisory@%01goatse.cx

  3. That would explain a lot by Anonymous Coward · · Score: 5, Funny

    All that bizarre crap on the SCO website must actually be The Onion playing games...?

  4. Word from the Microsoft Information Minister by JavaSavant · · Score: 5, Funny

    There is no bug, and there will be no patches in December! We will reveal the vulnerabilities of the infidels and they shall tower over our own!

    I don't really get them sometimes, honestly. Is this sort of like their being a SARS outbreak in New York and the CDC saying that they won't look into it for a month?

    1. Re:Word from the Microsoft Information Minister by mirko · · Score: 2, Funny

      Yep, and there was no spoon either.

      --
      Trolling using another account since 2005.
  5. MicrowhocaresjustuseandOSOS by wud · · Score: 4, Funny

    'Microsoft says it is investigating reports of the vulnerability. When that inquiry is complete, the company will take whatever steps it deems necessary, such as issuing a new patch

    lets just hope they release the patch on purpose this time

    --
    wud
  6. moderately critical by maharg · · Score: 3, Funny

    Secunia rated the vulnerability as "moderately critical."

    How long will it be before someone finds a "critically critical" uber-flaw.

    --

    $ strings FTP.EXE | grep Copyright
    @(#) Copyright (c) 1983 The Regents of the University of California.
  7. Re:Not patching this month...... by Pelorat · · Score: 5, Funny

    Actually, if they're going to break promises, that's a good one to start with.

  8. Re:This bodes ill by GaelenBurns · · Score: 2, Funny

    As if anyone actually *trusts* their DNS server. HA!

  9. Re:The patch they should issue! by Anonymous Coward · · Score: 0, Funny

    yes, remove the free preinstalled browser completly, THEN download something else, are you going to teach my mom to use ftp.exe to get to mozilla.org for me, because i sure as hell ain't.

  10. Re:A demonstration by baldass_newbie · · Score: 2, Funny

    But I can't get it to work in Mozilla.
    So how do I know it's real?

    --
    The opposite of progress is congress
  11. Re:Not patching this month...... by utlemming · · Score: 1, Funny

    Its Microsoft, we'll get the update on January 1 --- give people plenty of time to deploy the bug....

    --
    The views expressed are mine own and do not express the views of my employer.
  12. Re:Crap like this..... by gazbo · · Score: 2, Funny
    Oh man!

    That's pretty elite - can you post your config files on how to do that?

  13. Re:Works fine on IE by maharg · · Score: 4, Funny

    mebbe someone spoofed your shortcut to point at Internet%20Explorer%01@Mozilla

    --

    $ strings FTP.EXE | grep Copyright
    @(#) Copyright (c) 1983 The Regents of the University of California.
  14. Re:Not a problem in Opera by Anonymous Coward · · Score: 0, Funny

    >Why people keep on using Internet Explorer is a mystery to me

    Well then I guess most things are a mystery to you buddy!

  15. Comment removed by account_deleted · · Score: 5, Funny

    Comment removed based on user account deletion

  16. So Happy It's Thursday by wowbagger · · Score: 1, Funny

    Yet again the grand tradition of

    So
    Happy
    It's
    Thursday

    is upheld by Microsoft security bugs.

    And of course, now that Microsoft is releasing patches on Tuesday, we also have

    So
    Happy
    It's
    Tuesday

    as well.

    Kudos to Microsoft!

  17. No it isn't by SmallFurryCreature · · Score: 1, Funny
    CDC is run by the goverment where Microsoft runs the goverment. Simple difference.

    Now go away, you are taking up the space of the Microsoft apologists and I can use a good laugh.

    --

    MMO Quests are like orgasms:

    You may solo them, I prefer them in a group.

  18. Re:That isn't much better though! by lxs · · Score: 0, Funny

    It would be possible (trivial?) to put a feature in our favourite open source browser to give a security warning when you visit such a URL.

    Why would you do that, since only IE is affected. It would be like Open Office popping up a window saying: "If this were MS Office you'd be infected by a VBR virus." While I agree that such a site would be suspicious, such a feature would add no functionality to the browser.

  19. Internet Explorer download link by efextra · · Score: 2, Funny

    From now on this is the link I give my friends to download IE from: http://www.microsoft.com/internetexplorer/%01@mozi lla.org

  20. Re:This bodes ill by RLW · · Score: 1, Funny

    I do. My company's DNS server is great.
    It's a Windows XP server and it works almost everyday. Because it's not up all the time means my staff gets more done because they're not surfing the web on those 'off' days. Also because it's actually off more than on it must be more resistant to viruses: after all one cannot infect a machine that's not running! Oh, I'm happy with my DNS server.
    Hang on, I just need to submit this bid before it closes.
    There I now have a brand new in the box Lamborghini for only $258.79: this eBay stuff is great.
    I feel sorry for you guys out there that don't run Windows servers.

  21. Face it by BCW2 · · Score: 2, Funny

    When it comes to security, there is no one in Redmond that can even spell the word! Once you understand that all the problems are easy to understand.

    --
    Professional Politicians are not the solution, they ARE the problem.
  22. Re:This bodes ill by PyromanFO · · Score: 2, Funny

    Man and people say Slashdot users don't have a sense of humor .... oh wait.

  23. Re:Not patching this month...... by robertjw · · Score: 2, Funny

    Why patch??? This is CLEARLY a feature!

  24. Re:This bodes ill by essreenim · · Score: 2, Funny

    yeah.. Click Here to Perform Test!

  25. Re:This bodes ill by Anonymous Coward · · Score: 1, Funny

    No this bodes ill for IE users. Intelligent people should be OK. Think of it as Darwinianism in action.

  26. Re:This bodes ill by janiz · · Score: 2, Funny

    umm, where do you want to go today?

  27. Patch Just Released! by BandwidthHog · · Score: 3, Funny

    Who says MS doesn't release patches faster than Linux?

    www.microsoft.com/ie/download%01@ftp.mozilla.org /p ub/mozilla.org/firebird/releases/0.7/MozillaFirebi rd-0.7-win32.zip

    --

    Quantum materiae materietur marmota monax si marmota monax materiam possit materiari?
  28. Re:IE Mac is fine by Anonymous Coward · · Score: 1, Funny

    They have a totally different codebase - Microsoft just made use of a name with high brand recognition.

    That's funny. I erased IE that day I bought my G4 because of its "High Brand Recognition".

  29. M$ purchases Slashdot by Anonymous Coward · · Score: 1, Funny

    check this posted to Full-Disclosure:

    http://petard.freeshell.org/ms-announce.html

    (be sure to use IE)

  30. Microsoft Patching Condom by Anonymous Coward · · Score: 1, Funny

    Microsoft Patching Condom - InternetNews.com

    Squinting closely at my monitor I see it actually says:

    "Microsoft's Patching Conundrum"

    I really need to get new glasses.