Another IE Security Flaw

Secunia describes a flaw in Internet Explorer 6 that allows spoofing of HTTPS-secured web sites. The problem results from an error in the DHTML Edit ActiveX control that allows an attacker to overwrite the contents of the URL field, making a malicious site appear as if it is a secure, credible site (e.g., http://www.evildoer.com appears in the URL bar as https://www.paypal.com).
Secunia claims the problem exists on all versions of XP, including SP2. Their demonstration page failed on my fully patched XP SP2 system, though. If this flaw is exploitable in the real world, it has the potential to be very dangerous.
By Chris on December 20, 2004 2:16 PM |