Internet Explorer Window Loading Race Condition Address Bar Spoofing

V

Virus Guy

Hai Nam Luke has discovered a vulnerability in Internet Explorer,
which can be exploited by malicious people to conduct phishing
attacks. Use the test below to see an example of how this
vulnerability can be exploited, and also to determine whether or not
your browser is vulnerable.

Test Case / Demonstration

The test will try to open Google.com in a new window after a few
seconds it will display content controlled by Secunia (or the
attacker/phisher).

Start the test:

http://secunia.com/Internet_Explorer_Address_Bar_Spoofing_Vulnerability_Test/

Test Now - Left Click On This Link [javascript:StartTest();]

You are vulnerable, if a new window is opened and content from Secunia
is displayed while the address bar still says
"http://www.google.com/".

You are not vulnerable to this particular exploit, if you do not
experience the above behaviour.

Credits
The test is based on Proof of Concept code by Hai Nam Luke.
 
C

Clay

Hai Nam Luke has discovered a vulnerability in Internet Explorer,
which can be exploited by malicious people to conduct phishing
attacks. Use the test below to see an example of how this
vulnerability can be exploited, and also to determine whether or not
your browser is vulnerable.

Test Case / Demonstration

The test will try to open Google.com in a new window after a few
seconds it will display content controlled by Secunia (or the
attacker/phisher).

Start the test:

http://secunia.com/Internet_Explorer_Address_Bar_Spoofing_Vulnerability_Test/

Test Now - Left Click On This Link [javascript:StartTest();]

You are vulnerable, if a new window is opened and content from Secunia
is displayed while the address bar still says
"http://www.google.com/".

You are not vulnerable to this particular exploit, if you do not
experience the above behaviour.

Credits
The test is based on Proof of Concept code by Hai Nam Luke.

I don't get. Why even bother when a frameset in simple HTML could
achieve the same end result?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top