About Us | Contact Us
View Cart

Internet Explorer URL Spoofing Vulnerability

By Dan Hadaway | Wednesday, December 10, 2003 - Leave a Comment

An issue in Internet explorer will allow an attacker to take you to a page in your browser but the real URL will not show in the address bar. This also affects SSL – you will NOT be notified the SSL cert does not match the fake URL.

This might seem a trivial issue but the uses for the attacker are significant. For example, if an attacker sends you a URL to follow in the form of a forged email from your online bank, but the URL goes to their server rather than your bank. They could disguise this forgery, if you look at the address bar you’ll have no way of knowing you’re not really at your bank’s page.

The root issue in this bug is that you cannot trust where you think you may be in Internet Explorer. Whether you’re on your bank’s website or a Korean hacker’s, you’ll never know. There are many more ways this could be of use to an attacker, especially in conjunction with a number of other issues that remain unresolved.

As of this time there isn’t a patch or fix. The only real defense is to not use IE. Mozilla, Konqueror, and Opera are viable alternatives.

I’m trying my best not to be an IE basher, but it’s really hard not to…

Original disclosure:

Critical: Moderately critical
Impact: ID Spoofing
Where: From remote

Software: Microsoft Internet Explorer 6

Description:
A vulnerability has been identified in Internet Explorer, which can be exploited by malicious people to display a fake URL in the address bar.

The vulnerability is caused due to an input validation error, which can be exploited by including the \”%01\” URL encoded representation after the username and right before the \”@\” character in an URL.

Successful exploitation allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address bar, which is different from the actual location of the page.

This can be exploited to trick users into divulging sensitive information or download and execute malware on their systems, because they trust the faked domain in the address bar.

Example displaying only “http://www.trusted_site.com\” in the address bar when the real domain is \”malicious_site.com\”:
http://www.trusted_site.com%[email protected]_site.com/malicious.html

The vulnerability has been confirmed in version 6.0. However, prior versions may also be affected.

Solution:
Filter malicious characters and character sequences in a proxy server or firewall with URL filtering capabilities.

Don’t follow links from untrusted sources.

Posted in Vulnerability News

Related Articles
Latest News
    Community Banking and their layers of security. . . Michael Hartke’s first post as Executive Vice President! Thinking back to my first talk to security professionals in community banking almost 10 years ago, the question continues to this day. First some background… infotex was moderating the Indiana Bankers Association Security Conference when one of the […]
    Reasons why we should be considered! infotex provides a number of services that can be checked out if you click over to offerings.infotex.com! We even made a movie with all the reasons why infotex should be your next MSOC!  
    infotex and GoTo To all infotex managed security service Clients: As recently reported by major news outlets there was a data breach affecting GoTo (formerly LogMeIn) wherein attackers stole encrypted backups containing customer information in November 2022.  Based on the advisory from GoTo the products they offer that are affected include LogMeIn Pro, LogMeIn Central, […]
    An option for increasing security for ALL organizations. . . The threat landscape is evolving daily, and it is becoming increasingly difficult for even large organizations providing cyber defense services to keep up. As Brandao (2021) notes, it is important for organizations to adapt holistic technologies that can correlate all attack events. Therefore, developing XDR […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Check out posters.infotex.com for the whole collection! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape) You are welcome to print out and distribute this around your […]
    A relic of the internet’s less secure past, many small firms struggle to secure their email systems… An article review. With a great deal of cybersecurity related news focused on new threats and similarly new techniques aimed at combating them, it can be easy to forget some of the older threats that have never gone […]
    Seven Trends . . . …that small bank Information Security Officers face in 2023 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcome to the Magnificent Seven, my annual predictive article about the seven trends in technology that will impact the Information Security Officers of […]
    System Security and Cybersecurity are not the same thing. . . Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Regarding “information security,” the last thirty years have seen an evolution of frameworks, laws, and assessment approaches which intimidate the management team with their complexity.  […]
    The cryptographic algorithm is vulnerable to attack and is no longer considered secure… An article review. NIST has announced that it plans to retire the SHA-1 cryptographic algorithm by the end of 2030, citing multiple vulnerabilities in the standard, effectively ending its use after nearly 30 years.  Introduced in 1995, SHA-1 used a 160-bit hash […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Check out posters.infotex.com for the whole collection! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape) You are welcome to print out and distribute this around your […]