post Posted By: BioTecK

Microsoft confirmed a vulnerability Thursday in the address bar of Internet Explorer 7. First reported by security firm Secunia on Wednesday, the issue occurs in popup windows. It is possible to display a somewhat spoofed address bar, the company said.

Due to this issue, a specially crafted URL with special characters may hide portions of the address. This could open the user up to attacks, including performing actions that it may not be aware of. Secunia has rated the issue as “less critical,” its second lowest rating.
No attacks using this flaw are currently known, Microsoft said. It also recommended users make use of the Microsoft Phishing Filter that is included within IE7.

“The Microsoft Phishing Filter online service is designed to allow us to update it fairly quickly with information as sites are reported and confirmed by us,” Christopher Budd of the Microsoft Security Response Center Blog said.

“We do have this issue under investigation and as always, once we complete our investigation we’ll take appropriate steps to protect our customers,” he continued.
However, Budd downplayed the flaw, saying Microsoft’s research showed the full URL can still be displayed by clicking in the browser windows or address bar, or scrolling within the address bar.

Source:Betanews.com
—————————–
Mmm..another reason to use FireFox!! ;) Ow btw; FireFox 2.0 is download more than 2 million times in the first 24 hours after the launching of the new version.
You can get FireFox here!


| post Category: FireFox, General | post |

Sorry, no comments yet.

Write Your Comment

Comment Guidelines:
I encourage comments on this blog and really appreciate people taking the time to add a comment. I use dofollow and CommentLuv so there is more incentive to leave comments.
I get too much comment spam, so if you don’t see your comment immediately it’s because I have to moderate comments. Be patient, I'll approve it the minute I see it.

Basic XHTML is allowed. You can use these tags:
<a href="" title=""> <abbr title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>.
All line breaks and paragraphs will be generated automatically.

You should have a name, right? 
Your email address, I promised I won't tell it to anyone. 
If you have a web site or blog, you can type the URL right here. 
This is where you type your comments. 
Remember my information for the next time I visit.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word