This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Pop-up Loophole Opens Browsers To Phishing Attacks

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.eweek.com/print_article2/0,2533,a=140592,00.asp
December 8, 2004
" Security firm Secunia has warned that most Web browsers are vulnerable to a simple 'phishing' technique that could make fraudulent content appear genuine. The Copenhagen, Denmark, company on Wednesday published five advisories on the issue, covering fully patched, standard versions of Internet Explorer, Firefox, Opera, Konqueror and Safari. Secunia also published a demonstration allowing users to test their browsers. The test appeared to work on both Windows and Mac OS X platforms. The problem is in the way browsers handle pop-up windows, which are used by many trusted sites such as banks. Because browsers aren't designed to check whether another site is allowed to change the content of a pop-up window, a malicious site can insert its own content into any pop-up window, as long as the target name of the window is known, Secunia said…Secunia contacted the browser vendors before publishing the advisories, but so far none has issued patches or estimated when it might do so, according to Kristensen. "They consider it to be very basic functionality in the browser, which has been around for several years," he said…"

>>> http://secunia.com/multiple_browsers_windo…erability_test/

(Another suggested solution might include installation of: http://crypto.stanford.edu/SpoofGuard/ )

:blink: :blink:
FYI…

- http://isc.sans.org/diary.php?date=2004-12-10
Updated December 11th 2004 03:07 UTC
"Multiple Browsers Affected by a Window Injection Vulnerability
You may have already heard of a vulnerability, announced by Secunia on December 8th, which affects all commonly-used browsers. The vulnerability allows a website loaded in one browser window to control a pop-up that is opened from another window. The danger here is that a malicious site can spoof contents of a pop-up window that is opened from a trusted site, particularly in the context of phishing attacks.

We tested Secunia's proof-of-concept exploit code with Firefox, Internet Explorer, and Opera. The exploit worked as advertised. The workaround suggested by Secunia is: Do not browse untrusted sites while browsing trusted sites.
>>> We found another workaround that seems to work for users of Firefox: Install the Tabbrowser Extensions extension for Firefox. This extension allows Firefox users to control tabbed browsing features. Our limited tests suggest that installing this extension with default options makes Firefox immune to the proof-of-concept exploit.

The Secunia advisory:
- http://secunia.com/secunia_research/2004-13/advisory/
The Secunia proof-of-concept exploit to test your browser:
- http://secunia.com/multiple_browsers_windo…erability_test/
The Tabbrowser Extensions extension for Firefox:
- http://piro.sakura.ne.jp/xul/_tabextensions.html.en …"
FYI…

Opera Fix for Window Injection Vuln, Safari Work-around
- http://isc.sans.org/diary.php?date=2004-12-11

"…Opera has released a fix for the Window Injection Vulnerability mentioned in yesterday's diary. Get the fix here: http://www.opera.com/support/search/supsearch.dml?index=782

…Safari 1.2.4 (v125.12) on OS-X 10.3.6, is NOT vulnerable to the exploit if the pop-up blocker is enabled. It IS vulnerable if the pop-up blocker is disabled…"

:)
FYI…

Netcraft "anti-phishing" toolbar
- http://toolbar.netcraft.com/
"…The Toolbar community is effectively a giant neighbourhood watch scheme, empowering the most alert and most expert members to defend everyone within the community against phishing frauds. Once the first recipients of a phishing mail have reported the target URL, it is blocked for community members as they subsequently access the URL. Widely disseminated attacks (people constructing phishing attacks send literally millions of electronic mails in the expectation that some will reach customers of the bank) simply mean that the phishing attack will be reported and blocked sooner.

The Toolbar also:
* Traps suspicious URLs containing characters which have no common purpose other than to deceive.
* Enforces display of browser navigational controls (toolbar & address bar) in all windows, to defend against pop up windows which attempt to hide the navigational controls.
* Clearly displays sites' hosting location, including country, helping you to evaluate fraudulent urls (e.g. the real citibank.com or barclays.co.uk sites are unlikely to be hosted in the former Soviet Union)…"