NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


The Internet Explorer 7 "Matrix" Has You

A new vulnerability in IE7 will trap the users in a malformed web page

By Marius Oiaga, Technology News Editor

23rd of February 2007, 11:11 GMT

Adjust text size:


Yes, you have read right. The Internet Explorer 7 "Matrix" has you. A new vulnerability in Internet Explore 7 will trap the users in a malformed web page. Security company Secunia has issued
a public warning advising users about an error in the "onunload" events management in Internet Explorer 7. A successful exploit of this vulnerability will abort the loading process of a new website and redirect the user to a malicious web page. As of yet the vulnerability has been confirmed only in Internet Explorer 7, but other browsers may also be opened to attacks, and Firefox is a great candidate.

Exploits targeting the "onunload" vulnerability in IE7 will most likely be part of a spoofing/phishing attack. Users should take caution in knowing that the browser is vulnerable even if they enter the address manually in the IE7's address bar. The user will be trapped in the malformed webpage and the only way to get put would be to close down all the IE7 windows.

Security researcher Michal Zalewski explained the vulnerability:

"There is a cool combination-type vulnerability in MSIE7 that allows the attacker to:

a) Trap the visitor in a Matrix-esque tarpit webpage that cannot be left by normal means (this is a known brain-damaged design of onUnload Javascript handlers),
b) Spoof transitions between pages so that the user thinks he actually managed to leave the affected site, and so that the URL bar displays other addresses we didn't actually go to."

The vulnerability is a bundle between Javascript onUnload handler design and the way IE7 manages page transitions. The visitor will not only be trapped by the malicious webpage but also believe that the navigation took him to a legitimate address.
Read by 2,738 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.2/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 7 - Scarred By Vulnerabilities

The First Security Vulnerability in Internet Explorer 7

It's Raining Word Vulnerabilities

Microsoft Confirms Word 2000 Zero-Day

IE7 and Firefox 2.0 Share Vulnerabilities

Microsoft Responds to Symantec Claims of the Fifth Word Zero-Day

Highly Critical Microsoft Word Zero-Day

Microsoft Revamped IE Add-ons

Microsoft Updates the IE7 Phishing Filter

IE7 - the First Browser to Support EV SSL Certificates

Targeted Attack Scenario via a Microsoft Vulnerability

Internet Explorer 7 Blocks 1 Million Phishing Attacks Per Week

Microsoft Vulnerabilities in the Front Row at Super Bowl

A Bouquet of a Dozen Microsoft Security Bulletins, Please!

Gran Paradiso Alpha 2 Is Way Ahead of Internet Explorer 8.0

Internet Explorer 8.0 Available for Download on Peer-to-Peer Networks

Microsoft Confirms Fifth Office Zero-Day Vulnerability

The Windows Vista MessageBox Vulnerability Goes Unpatched

IE7 Mark of The Web

Microsoft Has No Plans to Enter the Vulnerabilities Market

Windows Vista Remote Execution Vulnerability

Paris Hilton's Pornography Exposed

IE7 Security Features Should, In Theory, Protect the Computer?

Windows Vista - Onward to the Slaughter

Microsoft Contracts Web Standards Evangelist

Microsoft's 12 Valentine Security Patches

Insight on the Latest Microsoft Office Zero-Day Vulnerability

Internet Explorer 7 Feeds Plus

Internet Explorer 8 Feature Survey Email

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM