New IE Exploit Spoofs Web Sites

edited December 2004 in Science & Tech
Security researchers have uncovered a spoofing flaw in Internet Explorer that could allow a scammer to display a fake Web site with all of the attributes of a genuine, secure site.
Security researchers have uncovered a spoofing flaw in Internet Explorer that could turn out to be the perfect holiday gift for scammers.

The bug, which has been confirmed on a fully patched Windows XP system with IE 6.0 and Service Pack 2, could allow a scammer to display a fake Web site with all the attributes of a genuine, secure site, including the URL and the icon indicating SSL security, according to researchers.

Because the vulnerability is found in one of Internet Explorer's default ActiveX controls, scammers could use it to spoof the content of any site, researchers said. Users could be lured to the fake site via a link in an e-mail message, a tactic that continues to prove effective despite efforts to educate users.
Source: eWeek

Comments

  • TroganTrogan London, UK
    edited December 2004
    I heard about this on Sky News. Some British people got emails pointing them to a fake website which appeared safe and asking for peoples bank details, names, house address etc.
  • TexTex Dallas/Ft. Worth
    edited December 2004
    Using to scam paypal users would be a problem too
Sign In or Register to comment.