Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Internet Explorer URL Spoofing Vulnerability

Thread Tools
 
Search this Thread
 
Old 10 December 2003, 03:09 PM
  #1  
Nicks VR4
Scooby Regular
Thread Starter
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Post

New issues with MS IE

And MS are not doing any patches the month

http://www.secunia.com/advisories/10395/

Internet Explorer URL Spoofing Vulnerability

Secunia Advisory: SA10395
Release Date: 2003-12-09

Critical: Moderately critical
Impact: ID Spoofing

Where: From remote

Software: Microsoft Internet Explorer 6
Description:
A vulnerability has been identified in Internet Explorer, which can be exploited by malicious people to display a fake URL in the address bar.

The vulnerability is caused due to an input validation error, which can be exploited by including the "%01" URL encoded representation after the username and right before the "@" character in an URL.

Successful exploitation allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address bar, which is different from the actual location of the page.

This can be exploited to trick users into divulging sensitive information or download and execute malware on their systems, because they trust the faked domain in the address bar.

Example displaying only "http://www.trusted_site.com" in the address bar when the real domain is "malicious_site.com":
http://www.trusted_site.com%01@malicious_site.com/malicious.html

The vulnerability has been confirmed in version 6.0. However, prior versions may also be affected.

Solution:
Filter malicious characters and character sequences in a proxy server or firewall with URL filtering capabilities.

Don't follow links from untrusted sources.



[Edited by Nicks VR4 - 12/10/2003 3:26:45 PM]
Old 10 December 2003, 05:19 PM
  #2  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Post

Better still, use another browser - IE is just not worth the hassle
Old 10 December 2003, 05:42 PM
  #3  
Miles
Scooby Regular
 
Miles's Avatar
 
Join Date: Oct 1998
Location: The Granite City/Dallas, Tx.
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Post

I've heard that other browsers suffer this vulnerability as well! Proof of concept at http://www.zapthedingbat.com/security/ex01/vun1.htm
Old 10 December 2003, 08:28 PM
  #4  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Post

Not that I'm bored or anything but,

Opera 6.03 OS X shows a blank in place of the hex char
Safari 1.1.1 OS X didn't do anything at all upon pressing the button
Opera 7.2 for Windows shows a square in place of the hex char
Opera 6.04 for Windows does the same as 7.2

No X server on the Linux machines or Solaris machines so I can't test.




All times are GMT +1. The time now is 10:28 PM.