<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; hacking-ie7</title>
	<atom:link href="http://www.darknet.org.uk/tag/hacking-ie7/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>IE 7 Flaw Could Help Phishers &#8211; Error Message Processing</title>
		<link>http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/</link>
		<comments>http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/#comments</comments>
		<pubDate>Wed, 18 Apr 2007 08:03:18 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-ie7]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7-flaw]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/</guid>
		<description><![CDATA[Ah another way for phishers and people wanting to steal login credentials to con IE7 users. Yet another reason to use Firefox or Opera? Not saying these browsers are perfect&#8230;but look at the amount of problems Internet Exploder Explorer has had. The flaw lies in the way IE7 processes a locally stored HTML error message [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah another way for phishers and people wanting to steal login credentials to con IE7 users.</p>
<p>Yet another reason to use Firefox or Opera?</p>
<p>Not saying these browsers are perfect&#8230;but look at the amount of problems Internet <del datetime="2007-04-18T07:58:30+00:00">Exploder</del> Explorer has had.</p>
<blockquote><p>The flaw lies in the way IE7 processes a locally stored HTML error message page that is typically shown when the user cancels the loading of a Web page, said Aviv Raff, a security researcher based in Israel.</p>
<p>The error message tells the user that &#8220;navigation to the Web page was canceled,&#8221; and offers the user the opportunity to &#8220;refresh the page.&#8221; If the refresh link is clicked, IE can be tricked into displaying the wrong Web address for a page. Raff has published proof of concept code that shows how IE can be made to display a Web page on his Web site as if it is from the cnn.com domain. </p></blockquote>
<p>I&#8217;m not sure if any phishers would go to this length to try and con people into visiting their sites, but with some of the creative things they&#8217;ve been coming up with lately, it wouldn&#8217;t surprise me!</p>
<blockquote><p>This flaw could be exploited by phishers who want to make their spoofed Web sites appear legitimate, Raff said.</p>
<p>&#8220;I can inject a script that will display anything I want in the page when the user clicks the &#8216;refresh&#8217; link,&#8221; he said via instant message. &#8220;Combining this with the design flaw, an attacker can render in the browser whatever he wants with whatever URL he wants in the address bar.&#8221;</p>
<p>This type of bug is known as a cross-site scripting vulnerability. It affects IE 7 on Vista and Windows XP, Raff added.</p></blockquote>
<p>Vista is vulnerable too, so be careful. And don&#8217;t use IE!</p>
<p><em>Yes this article was originally published about a month ago, we know that&#8230;.thanks.</em></p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2007/031407-new-ie-7-bug-could.html?fsrc=rss-security">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D508+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;t=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F04%2Fie-7-flaw-could-help-phishers-error-message-processing%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

