Digital Edition

SYS-CON.TV
Microsoft Issues Phishing Security Advisory For IE Users
Browser Windows Without Indications of Their Origins May Be Used in Phishing Attempts

Microsoft has investigated a public report of a phishing method that affects Web browsers in general, including IE - a report that describes the scenario of multiple, overlapping browser windows, some of which contain no indications of their origin. An attacker could arrange windows in such a way as to trick users into thinking that an unidentified dialog or pop-up window is trustworthy when it is in fact fraudulent.

"When a user visits a malicious Web site the user may be redirected to a trusted Web site," says the Microsoft Security Advisory No. 902333 released Tuesday. "The attacker could then display an overlapping window in the form of a dialog box attempting a phishing attack. The user is then prompted to input personal information into this dialog box, which was opened from the malicious Web site. The user might believe that this dialog box was opened by the trusted Web site and they might input personal information. However, this information is sent to the malicious Web site."

The advisory continues:

"Customers who already follow our general guidance about avoiding spoofing and phishing attacks are at reduced risk of being affected by this issue. If a particular window or dialog box does not have an address bar and does not have a lock icon that can be used to verify the site’s certificate, the user is not provided with enough information on which to base a valid trust decision about the window or dialog box. To view Microsoft’s general guidance about how to avoid spoofing attacks visit the Security at Home Web site.

We continue to encourage customers install Windows XP SP2 and to follow our Protect Your PC guidance of enabling a firewall. This includes turning on Automatic Updates to receive software updates and installing anti virus software."

About Security News Desk
SYS-CON's Security News desk trawls the world of security for news of software, hardware, products, and services that seems likely to be of interest to infosec professionals and summarizes them for easy assimilation by busy IT managers and staff.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1



ADS BY GOOGLE
Subscribe to the World's Most Powerful Newsletters

ADS BY GOOGLE

At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with exp...
When a company wants to develop an application, it must worry about many aspects: selecting the infr...
Financial enterprises in New York City, London, Singapore, and other world financial capitals are em...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with exp...
Darktrace is the world's leading AI company for cyber security. Created by mathematicians from the U...
DevOps has long focused on reinventing the SDLC (e.g. with CI/CD, ARA, pipeline automation etc.), wh...
Cloud Storage 2.0 has brought many innovations, including the availability of cloud storage services...
Most modern computer languages embed a lot of metadata in their application. We show how this goldmi...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with exp...
Every organization is facing their own Digital Transformation as they attempt to stay ahead of the c...
Intel is an American multinational corporation and technology company headquartered in Santa Clara, ...
Data center, on-premise, public-cloud, private-cloud, multi-cloud, hybrid-cloud, IoT, AI, edge, SaaS...
Atmosera delivers modern cloud services that maximize the advantages of cloud-based infrastructures....
Today's workforce is trading their cubicles and corporate desktops in favor of an any-location, any-...
Artifex Software began 25-years ago with Ghostscript, a page description language (PDL) interpreter ...
ShieldX's CEO and Founder, Ratinder Ahuja, believes that traditional security solutions are not desi...
Is your enterprise growing the right skills to fight the digital transformation (DX) battles? With 6...
In an age of borderless networks, security for the cloud and security for the corporate network can ...
Now is the time for a truly global DX event, to bring together the leading minds from the technology...
Moving to Azure is the path to digital transformation, but not every journey is effective. Organizat...