Slashdot Mirror


New URL Spoofing Bug in Pre-SP2 IE

An anonymous reader writes "According to Netcraft a new security flaw has been found in Microsoft Internet Explorer which makes it possible to spoof a URL with just some simple HTML code, by enclosing two URLs and a table within a single href tag. The user will be sent to one site, but the status bar will show a fake URL. The bug apparently affects IE and Outlook Express up to but not including SP2. Firefox and Konqueror seem unaffected."

17 of 266 comments (clear)

  1. Comment removed by account_deleted · · Score: 5, Informative

    Comment removed based on user account deletion

  2. Safari is affected also by dereklam · · Score: 5, Informative

    This exploit also affects Safari 1.2.3 on Panther.

  3. Safari by P-Nuts · · Score: 4, Informative

    Worryingly, Safari is also fooled by the bug - the status bar shows http://www.microsoft.com/ before you click on the link, but the address bar in the resulting window correctly shows http://www.google.com/.

  4. A sample of what it looks like by grahamsz · · Score: 4, Informative

    http://graha.ms/iesploit.html

    Doesn't seem like anything that couldn't be done with javascript.

  5. Sort of ... by Dlugar · · Score: 4, Insightful

    Just tested it with Opera 7.54 for Linux ... if you mouseover the actual text, "google.com" shows in the status bar, but if you position your cursor just exactly so that it's kinda over the URL, but not over any of the text, then you can get "microsoft.com" to show.

    But I'm kind of confused as to why this is a big deal ... can't you just use Javascript to rewrite the status bar anyway?

    Dlugar

    --
    Computer Go: Writing Software to Play the Ancient Game of Go
  6. Re:Safari Affected? by bmoore · · Score: 4, Informative

    Interesting... VERY interesting... I also have Safari 1.2.3, v125.9. When I hover my mouse over the link, it shows www.microsoft.com in the status bar. If I click the link, I go to google, but if I r-click and choose "Open Link in New Tab" (or new window) I go to www.microsoft.com.

    Odd. Very odd. Hopefully Apple will arrange for some consistency in operation soon.

  7. IE users.. by Xeo+024 · · Score: 5, Informative
    To test the URL simply right-click it and it'll display the real URL, if that doesn't work right-click it and go to properties.

    But your best bet would be to either update or switch to an unaffected browser.

  8. What's worse? by nile_list · · Score: 5, Interesting

    What's worse? IE being vulnerable to spoofed URLs because of malformed HTML, or Firefox crashing because of the same thing?

    --
    Gnash Gnash Gnash
  9. affected my Safari :-( by quacking+duck · · Score: 4, Insightful

    Just tried it myself on Safari v125.9 on 10.3.5; unfortunately the spoof worked.

    Hovering over the actual link showed microsoft.com in the status bar, but clicking it did indeed go to google.

    However, I can click outside the link on the same line (thanks to the table spanning the entire width of the article box), and it'll go to microsoft.com as indicated in the status bar when howevering over the line.

  10. Re:Patch by Anonymous Coward · · Score: 5, Funny
  11. It SORT OF affects SP2! by SnprBoB86 · · Score: 4, Informative

    With my SP2 system I naviagated to http://graha.ms/iesploit.html/ and hovered over the link. This is what I discovered:

    If you place the mouse on the link it shows the link will take you to google as it should, but if you place the mouse just outside the link (I guess on the table border) it says microsoft. The kicker is, that when it says Microsoft, clicking the link will not do anything.

    --
    http://brandonbloom.name
  12. Safari goes to wrong place by goynang · · Score: 4, Insightful

    Safari goes to the wrong URL too.

    Just tried the demo and ended up at Google rather than where the link looked like it should go.

    Damn!

  13. Status bar? by FearUncertaintyDoubt · · Score: 4, Insightful
    I can see how this is a bug, and should be fixed, but how big of a security risk is it really? I think anyone aware enough to look at the status bar will probably look at the address bar in the browswer, which will show the real URL. So, yes, the status bar spoof might get someone to click, but they can't spoof the address bar, and a phishing scam would fall apart at that point.

    You might as well say that links themselves are a security risk, since a link that says "Microsoft Web Site" but really goes to goatse.cx is a dangerous spoof.

  14. Firefox 1.0RC1 **IS** affected by Ark42 · · Score: 5, Informative

    Change the html from
    <a href="http://www.microsoft.com/"><table><tr><td><a href="http://www.google.com/">http://www.microsoft .com</td></tr></table></a>
    to
    <a href="http://www.microsoft.com/"><table><tr><td><a href="http://www.google.com/">http://www.microsoft .com</a></td></tr></table></a&gt ;

    (sorry, Extrans mode is breaking the last </a> for some reason there)

    and you will notice the status bar says microsoft.com, and clicking it goes to microsoft.com, but middle click for a new tab, and you get google, not what the status bar says!

    1. Re:Firefox 1.0RC1 **IS** affected by Deviate_X · · Score: 5, Interesting

      That didn't work in my 1.0PR (Win) but this did:

      <a href="http://www.microsoft.com/" onclick="location.href='http://www.google.com/';
      return false">
      http://www.microsoft.com
      </a> ...

    2. Re:Firefox 1.0RC1 **IS** affected by JPriest · · Score: 4, Insightful

      So Firefox is affected and IE SP2 is not. This story is just more MS bashing FUD.

      --
      Saying Java is nice because it works on all OS's is like saying that anal sex is nice because it works on all genders.
  15. Re:Come on people! by secolactico · · Score: 5, Funny

    That's nothing. *My* father installed SP2 against my recommendation, and the next day a burglar broke into his house and stole most of the silverware!

    Since installing firefox, nobody has broken into his house again.

    --
    No sig