Phishing Emails Exploit Browser Weaknesses

Reviews
Shared by: Gilbert Zammit
Categories
Stats
views:
20
rating:
not rated
reviews:
0
posted:
10/8/2008
language:
pages:
0
Phishing Emails Exploit Browser Weaknesses Most web browsers are supposed to protect people by implementing security zones. These safe zones use different security settings of a web browser, which can vary based on the location of the web page being viewed. Phishing emails can lure users to a malicious code web site. These sites attempt to install spyware, malware or both onto the unknowing person’s computer. These web sites rely on weaknesses in web browsers, which will allow installation and execution of harmful programs on a computer. These web browser vulnerabilities allow overriding settings, even when these sites are located in a security zone that is not trusted and normally would not allow those actions. Here are a couple of weak spots, as identified by the CERT Coordination Center: 1. Outlook Express HTML protocol handler does not properly validate location of alternate data This is a cross-domain vulnerability where a specifically formatted URL invoking the InfoTech Storage (ITS)2 format protocol handlers could cause Internet Explorer to load an HTML document located within a Microsoft HTML Help (CHM) file. This HTML document would then be rendered in the Local Machine Zone. This HTML document could contain a script, ActiveX object, or IFRAME element to download and execute malicious code. We have observed this vulnerability used extensively in attempts to install malware. Read the rest of this article

Related docs
Technical Trends in Phishing Attacks
Views: 14  |  Downloads: 0
Banking On Phishing
Views: 6  |  Downloads: 2
anti phishing
Views: 143  |  Downloads: 5
Phishing_with_a_Net
Views: 0  |  Downloads: 0
Phishing Research
Views: 23  |  Downloads: 3
Phishing
Views: 20  |  Downloads: 6
Phishing
Views: 32  |  Downloads: 0
premium docs
Other docs by Gilbert Zammit
236Million and
Views: 10  |  Downloads: 0
Spammers Once Again Attacking Microsoft
Views: 33  |  Downloads: 0
Email stubbing not always a good idea
Views: 35  |  Downloads: 0
Administrator Swiss Army Knife
Views: 18  |  Downloads: 0