The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Security Advisories (RSS) - Microsoft
Google UNIX.COM


Security Advisories (RSS) - Microsoft Microsoft Security Advisories Via RSS News

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Microsoft Security Advisory (951306): Vulnerability in Windows Could Allow Elevation iBot Security Advisories (RSS) - Microsoft 0 04-23-2008 02:20 PM
Microsoft Security Advisory (951306): Vulnerability in Windows Could Allow Elevation iBot Security Advisories (RSS) - Microsoft 0 04-17-2008 10:10 PM
Microsoft Security Advisory (943521): URL Handling Vulnerability in Windows XP and Wi iBot Security Advisories (RSS) - Microsoft 0 12-24-2007 06:00 AM
Microsoft Security Advisory (922582): Update for Windows - 9/12/2006 iBot Security Advisories (RSS) - Microsoft 0 12-24-2007 06:00 AM
Microsoft Security Advisory (914457): Vulnerability in Windows Service ACLs - 3/14/20 iBot Security Advisories (RSS) - Microsoft 0 12-24-2007 06:00 AM

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-24-2007
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,302
Microsoft Security Advisory (902333): Browser windows without indications of their or

Revision Note: Advisory published. Advisory Summary:Microsoft has investigated a public report of a phishing method that affects Web browsers in general, including Internet Explorer. The report describes the scenario of multiple, overlapping browser windows, some of which contain no indications of their origin. An attacker could arrange windows in such a way as to trick users into thinking that an unidentified dialog or pop-up window is trustworthy when it is in fact fraudulent. When a user visits a malicious Web site the user may be redirected to a trusted Web site. The attacker could then display an overlapping window in the form of a dialog box attempting a phishing attack. The user is then prompted to input personal information into this dialog box, which was opened from the malicious Web site. The user might believe that this dialog box was opened by the trusted Web site and they might input personal information. However, this information is sent to the malicious Web site. Browser Windows Without Indications of Their Origins may be Used in Phishing Attempts. Customers who already follow our general guidance about avoiding spoofing and phishing attacks are at reduced risk of being affected by this issue. If a particular window or dialog box does not have an address bar and does not have a lock icon that can be used to verify the siteâ??s certificate, the user is not provided with enough information on which to base a valid trust decision about the window or dialog box. To view Microsoftâ??s general guidance about how to avoid spoofing attacks visit the Security at Home Web site.

More...
Reply With Quote
Google UNIX.COM
Forum Sponsor
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 08:56 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0