CERT-In Vulnerability Note
CIVN-2003-0016
Microsoft Internet Explorer does not properly display URLs .
Original Issue Date:December 31, 2003
Severity Rating: MEDIUM
Systems Affected
Internet Explorer 5.0 Internet Explorer 5.0.1 SP3 Internet Explorer 5.0.1 SP2 Internet Explorer 5.0.1 SP1 Internet Explorer 5.0.1 Internet Explorer 5.5 SP2 Internet Explorer 5.5 SP1 Internet Explorer 5.5 Internet Explorer 6.0 SP1 Internet Explorer 6.0
Overview
A vulnerability has been reported in Microsoft Internet Explorer; according to this a vulnerable version of IE does not properly display the location of HTML documents.
Impact
The vulnerability exposes the user of IE to social engineering attacks, by which an attacker could mislead a user into disclosing sensitive information.
Description
Microsoft Internet Explorer IE does not properly display URLs in the address bar that contains certain non-printable characters. IE may connect to one address but display a different address.
A class of social engineering attacks known as phishing , attempts to mislead a user into visiting a web site that appears to be legitimate but is in fact under the control of an attacker. The attacker may disguise the actual location of a URL by populating <userinfo> with credible data and obfuscating <host>:<port> with various URL representations, URL encoding, or other similar techniques. The attacker seeks to convince the user to provide sensitive information credit card numbers, personal information, etc. by making the web site appear legitimate.
This reported vulnerability significantly adds to the attackers ability to mislead users, since only <userinfo> is visible, not the actual location of the URL.
Workaround
Do not click on URLs from untrusted sources such as unsolicited email or instant messages. Type URLs or use trusted bookmarks for sensitive sites. Users are also advised to check the credentials of the website they are accessing and verify authenticity of the website before disclosing any sensitive information like credit card details, personal information, etc.
Vendor Information
Microsoft Microsoft Knowledge Base Article - 833786
References
CERT/CC Vulnerability Note VU#652278
http://www.kb.cert.org/vuls/id/652278
Microsoft Knowledge Base Article - 833786
http://support.microsoft.com/?id=833786
Internet Explorer URL Spoofing Vulnerability
http://www.secunia.com/advisories/10395/
Multiple Browser URI Display Obfuscation Weakness
http://www.securityfocus.com/bid/9182
Microsoft Internet Explorer domain URL spoofing
http://xforce.iss.net/xforce/xfdb/13935
Phishing Definition
http://www.webopedia.com/TERM/p/phishing.html
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|