AplusWebMaster
Topic Starter
FYI…
- http://www.eweek.com/print_article2/0,2533,a=140592,00.asp
December 8, 2004
" Security firm Secunia has warned that most Web browsers are vulnerable to a simple 'phishing' technique that could make fraudulent content appear genuine. The Copenhagen, Denmark, company on Wednesday published five advisories on the issue, covering fully patched, standard versions of Internet Explorer, Firefox, Opera, Konqueror and Safari. Secunia also published a demonstration allowing users to test their browsers. The test appeared to work on both Windows and Mac OS X platforms. The problem is in the way browsers handle pop-up windows, which are used by many trusted sites such as banks. Because browsers aren't designed to check whether another site is allowed to change the content of a pop-up window, a malicious site can insert its own content into any pop-up window, as long as the target name of the window is known, Secunia said…Secunia contacted the browser vendors before publishing the advisories, but so far none has issued patches or estimated when it might do so, according to Kristensen. "They consider it to be very basic functionality in the browser, which has been around for several years," he said…"
>>> http://secunia.com/multiple_browsers_windo…erability_test/
(Another suggested solution might include installation of: http://crypto.stanford.edu/SpoofGuard/ )

- http://www.eweek.com/print_article2/0,2533,a=140592,00.asp
December 8, 2004
" Security firm Secunia has warned that most Web browsers are vulnerable to a simple 'phishing' technique that could make fraudulent content appear genuine. The Copenhagen, Denmark, company on Wednesday published five advisories on the issue, covering fully patched, standard versions of Internet Explorer, Firefox, Opera, Konqueror and Safari. Secunia also published a demonstration allowing users to test their browsers. The test appeared to work on both Windows and Mac OS X platforms. The problem is in the way browsers handle pop-up windows, which are used by many trusted sites such as banks. Because browsers aren't designed to check whether another site is allowed to change the content of a pop-up window, a malicious site can insert its own content into any pop-up window, as long as the target name of the window is known, Secunia said…Secunia contacted the browser vendors before publishing the advisories, but so far none has issued patches or estimated when it might do so, according to Kristensen. "They consider it to be very basic functionality in the browser, which has been around for several years," he said…"
>>> http://secunia.com/multiple_browsers_windo…erability_test/
(Another suggested solution might include installation of: http://crypto.stanford.edu/SpoofGuard/ )