Spyware, Viruses, & Security forum

General discussion

Vulnerability - May 2, 2004

by Donna Buenaventura / May 2, 2004 2:37 AM PDT

Microsoft Internet Explorer SSL Icon Error May Let Remote Users Impersonate Secure Web Sites

SecurityTracker Alert ID: 1010009
CVE Reference: GENERIC-MAP-NOMATCH
Date: Apr 30 2004

Impact: Modification of system information, Modification of user information

Exploit Included: Yes

Version(s): 6.0.2800

Description: A vulnerability was reported in Microsoft Internet Explorer. A remote user can employ another site's certificate to cause the target user's browser to appear to be connected to the other site.

Emmanouel Kellinis reported that a remote user can invoke a combination of a META Refresh operation and an OnUnload BODY tag to partially impersonate a secure web site.

A remote user can create HTML that will perform a zero second refresh to the target secure web site. The HTML will also include a BODY onUnload operation using the window.location method:

< BODY onUnload='window.location=""' >

This will reportedly cause the browser to ask the target user if the certificate for the target secure web site should be trusted and then, if the target user responds to the affirmative, display the content of the security site. The URL will display the correct URL (of the malicious web site), however, the content will be that of the target web site and the SSL lock will be displayed in the target user's browser, the report said.

According to the report, if the target user clicks on the SSL lock icon, the browser will indicate that the page's certificate is not valid.

A demonstration exploit page is provided in the Source Message.

Impact: A remote user can create a malicious web site that, when loaded by the target user, may appear to be another secure web site [however, the URL will still be accurate]. A remote user can exploit this flaw to attempt "phishing" scams.

Solution: No solution was available at the time of this entry.

Vendor URL: www.microsoft.com/technet/security/

Cause: Authentication error, State error

Underlying OS: Windows (Any)

Reported By: "E.Kellinis"

http://www.securitytracker.com/alerts/2004/Apr/1010009.html

Discussion is locked
You are posting a reply to: Vulnerability - May 2, 2004
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: Vulnerability - May 2, 2004
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Popular Forums
icon
Computer Newbies 10,686 discussions
icon
Computer Help 54,365 discussions
icon
Laptops 21,181 discussions
icon
Networking & Wireless 16,313 discussions
icon
Phones 17,137 discussions
icon
Security 31,287 discussions
icon
TVs & Home Theaters 22,101 discussions
icon
Windows 7 8,164 discussions
icon
Windows 10 2,657 discussions

GIVEAWAY

Turn up the volume with our Apple Byte sweeps!

Two lucky winners will take home the coveted smart speaker that lets Siri help you around your connected house. This sweepstake ends Feb. 25, 2018.