|
|
|
|
![]() ![]() |
Jun 22 2005, 02:10 AM
Post
#1
|
|
|
Premium Member Group: Members Posts: 352 Joined: 2-March 05 From: Australia Member No.: 2,859 |
According eWeek.com, a new vulnerability was found in all the major Web browsers ( IE, Firefox, Safari).
This Spoofing Flaw can be exploited by malicious hackers to trick surfers into disclosing confidential information. QUOTE "The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open a prompt dialog box, which appears to be from a trusted site," Here is the place for you to test your broswer whether vulnerable or not. http://secunia.com/multiple_browsers_dialo...erability_test/ source: http://www.eweek.com/article2/0,1759,1830025,00.asp |
|
|
|
Jun 22 2005, 02:53 AM
Post
#2
|
|
|
Premium Member Group: Members Posts: 218 Joined: 14-March 05 From: Singapore Member No.: 3,041 myCENTs:92.74 |
Oh dear, this sounds pretty serious. All my browsers are vulnerable... O-o. Wonder whether there'd be any patch soon?
|
|
|
|
Jun 22 2005, 04:36 AM
Post
#3
|
|
|
Premium Member Group: Members Posts: 382 Joined: 5-September 04 Member No.: 255 |
Hmmn... I'm wondering, if these security flaws were not made public, would potential hackers have found out about and sicovered the flaw? Do they go about engineering and looking at the source code to disocver new flaws?
|
|
|
|
Jun 22 2005, 11:47 AM
Post
#4
|
|
|
Bursting with vegany goodness! Group: Members Posts: 342 Joined: 8-April 05 From: Norwich, UK Member No.: 3,753 myCENTs:10.76 |
I honestly don't see how that is a security problem. Surely even a completely inexperienced computer user would notice the new window opening when they clicked the link. Even if they didn't, who would be stupid enough to enter bank account details into a completely unsecure javascript dialogue?
To be honest, I doubt scammers will be adopting this method quite soon |
|
|
|
Jun 22 2005, 01:32 PM
Post
#5
|
|
|
Premium Member Group: Members Posts: 218 Joined: 14-March 05 From: Singapore Member No.: 3,041 myCENTs:92.74 |
Hmm, I don't know, for me the very fact that they can open a unnamed javascript window on top of a verified site is still rather disturbing. Yes, even a new computer user would notice the new window opening, but it's not the noticing the new window, it's more of if the hacker decides to exploit the vulnerability, makes his pop-up dialog box really authentic-looking, and thus gets information from not-so-experienced computer users, and then use that information. I mean, I think people like my dad or my brother, though they are not total-computer-idiots, might fall for a dialog box that seems to come from Google.com or Amazon.com asking for passwords or stuff like that.
|
|
|
|
Jun 25 2005, 08:09 AM
Post
#6
|
|
|
Premium Member Group: Members Posts: 352 Joined: 2-March 05 From: Australia Member No.: 2,859 |
I just saw this new in C|Net News.com.
[quota] Microsoft does not plan to update Internet Explorer to prevent a spoofing attack that could trick users into giving out personal information to hackers. [/quota] Is it just because thuse they don't deem them a high risk?? Do you believe this article?? I am quite surprise, microsoft won't issue an update for IE. it makes IE is the worst browser right now. source: http://news.com.com/IE+pop-up+spoof+wont+g...ml?tag=nefd.top |
|
|
|
Jun 26 2005, 12:48 AM
Post
#7
|
|
|
Newbie [ Level 1 ] Group: Members Posts: 3 Joined: 26-June 05 Member No.: 6,590 |
Firefox's Javascrips Is Kinda Messed Upp Dont Ya Think ???? XX
|
|
|
|
Jun 28 2005, 09:19 PM
Post
#8
|
|
|
Newbie [ Level 2 ] Group: Members Posts: 12 Joined: 31-May 05 Member No.: 5,632 |
and this is just one more reason why i have javascript disables in all my browsers. i didnt get the prompt so i assume i dont have that particul insecurity to worry about
|
|
|
|
Jun 29 2005, 04:09 AM
Post
#9
|
|
|
Super Member Group: Members Posts: 692 Joined: 25-November 04 Member No.: 1,523 |
As more such problems are discovered, programmers will learn to be more and more security savvy. Open source has the best chances though. The people who are open source tend to care about security, and having their programs work. So, it will probably get fixed in FF in the not too distant future. IE may have to wait till version 7, whenever the hell that comes out.
|
|
|
|
Jun 29 2005, 04:24 AM
Post
#10
|
|
|
Member - Active Contributor Group: Members Posts: 90 Joined: 29-June 05 Member No.: 6,693 |
Oof. Thanks for the example you provided. Now I know what it looks like. Good thing banks don't use JS prompts, or hackers could steal credit card information. Hope Microsoft fixes it soon
|
|
|
|
![]() ![]() ![]() |
Similar Topics
|
Lo-Fi Version | Time is now: 5th December 2008 - 03:24 PM |