New IE 7 bug could help phishers


A vulnerability in Internet Explorer (IE) browser could make phishing websites appear genuine, a security researcher has reported. The flaw lies in the way IE7 processes a locally stored HTML error message page that is typically shown when the user cancels the loading of a web page, said Aviv Raff, a security researcher based in Israel.

The error message tells the user that "navigation to the webpage was cancelled," and offers the user the opportunity to "refresh the page." If the refresh link is clicked, IE can be tricked into displaying the wrong web address for a page. Techworld.com - Computer & Internet Security News - New IE 7 bug could help phishers

Linked by shanmuga Thursday, 15th March 2007 1:11AM