»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 12-12-2003, 08:43 AM   #1 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Ooltewah, TN
Posts: 483
LittleKing is on a distinguished road
Send a message via Yahoo to LittleKing
Security Spoofing vulnerability in IE

I don't know if anybody has posted about this or not (since I haven't been on the boards for a while) but there is a spoofing security vulnerablity in IE. More info can be found at TheInquirer.net.

Apprently this also can partially affect Mozilla browsers as well.

Here you can test to see if you are vulnerable.

Just wanted to make you guys aware of this.

LK

LittleKing is offline   Reply With Quote
Old 12-12-2003, 08:52 AM   #2 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Combine that spoof with the fake Paypal and ebay emails and you have a potentially nasty problem for most users.

So don't follow links from untrusted sources!
DVNT1 is offline   Reply With Quote
Old 12-12-2003, 09:31 AM   #3 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
The more I think about it, the more I realize it is a big issue.

For example, so many accounts are being compromised do to the html email that shows http://signin.ebay.com//aw-cgi/eBayI...ame=h:h:sin:US but really directs you some malicious site just showing http://192.168.28.97/aw-cgi/eBayISAP...ame=h:h:sin:US and displaying the exact same content.

Now this exploit hides the IP portion from the URL and displays the trusted site name, but you still go to the malicious site in the background!

Last edited by DVNT1; 12-12-2003 at 09:34 AM.
DVNT1 is offline   Reply With Quote
Old 12-12-2003, 10:10 AM   #4 (permalink)
Registered User
 
jmichna's Avatar
 
Join Date: Oct 2001
Location: Chicagoland IL
Posts: 1,539
jmichna is on a distinguished road
My wife -- a frequent eBay user -- has gotten literally dozens of the "eBay" requests for her to confirm her username/password, other "her account will be terminated" or some such nonsense.

Fortunately, she is not gullible ( I've managed to convey a certain amount of cyber-cynicism ).

These emails are REALLY well done, and look like the real deal, including links to (certain) legitimate eBay pages.

She forwards them to a security section of eBay (don't recall exactly where) and then eBay pursues. I've looked at the email header info, and most of these are from a European server source.

Another thing I've seen people get are e-mails -- purportedly from Microsoft -- telling the recipient to run an attached (executable) file for some "security issue."

Again, the uninfomed/ill-informed would likely do so (the letters are well done, and look like they are from M$!)... but Microsoft NEVER sends users any sort of patch/upgrade as an attachment. You need to go to the MS Update site.
__________________
A man becomes rich not by having what he wants, but by wanting what he haves.
jmichna is offline   Reply With Quote
Old 12-12-2003, 01:27 PM   #5 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Also see http://www.techimo.com/forum/t92100.html for an example I created.
DVNT1 is offline   Reply With Quote
Old 12-12-2003, 03:37 PM   #6 (permalink)
Registered User
 
Starfury_2260's Avatar
 
Join Date: Aug 2003
Location: KY
Posts: 1,092
Starfury_2260 is on a distinguished road
now how can you stop it?
__________________
Heatware: Starfury
Ebay feedback: starfury_2260
Starfury_2260 is offline   Reply With Quote
Old 12-12-2003, 04:59 PM   #7 (permalink)
Registered User
 
jmichna's Avatar
 
Join Date: Oct 2001
Location: Chicagoland IL
Posts: 1,539
jmichna is on a distinguished road
Quote:
Originally posted by Starfury_2260
now how can you stop it?
We forward what we receive to the company being spoofed/victimized. Most have a section like eBay's "Safe Harbor."
__________________
A man becomes rich not by having what he wants, but by wanting what he haves.
jmichna is offline   Reply With Quote
Old 12-12-2003, 08:19 PM   #8 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Quote:
Originally posted by Starfury_2260
now how can you stop it?
When you receive an email that looks legitimate and you think may need to logon to that site... directly type the URL into your browser, don't trust the hyperlink in the email. Even a copy & paste of the link should work, just be sure to examine the pasted link for the @ sign or anything else that isn't common (also numeric addresses in place of domains is rarely legitimate).
DVNT1 is offline   Reply With Quote
Old 12-12-2003, 08:42 PM   #9 (permalink)
Registered User
 
Derek79602+'s Avatar
 
Join Date: Oct 2001
Location: Abilene, TX USA
Posts: 764
Derek79602+ is on a distinguished road
Quote:
Originally posted by Starfury_2260
now how can you stop it?
Answer to that question.

Opera freaks out when I try to go to any of those "modified" sites and ask me, "are you sure you want to do this?"

It also shows the REAL address when you do a mouseover.
__________________
My wife is a hottie.
Derek79602+ is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:57 AM.