Page 1 of 1

Phishing with Google courtesy of IE

Posted: Sun Dec 04, 2005 1:43 am
by Endo
An Israeli hacker has discovered and published a vulnerability in Microsoft's Internet Explorer (IE) browser, that could allow a malicious user to use the Google Desktop software to access confidential information.

Such information could be credit card numbers and even passwords.

The hacker, Matan Gillon believes the flaw involves cross-domain protections in Internet Explorer and works on fully patched IE browsers with Google Desktop (2) installed.

Graham Cluley, senior technology consultant at Sophos, said he is concerned that Gillon did not reveal the flaw responsibly.

Some analysts believe Gillon has exacberated the problem by going public without working with Google and Microsoft before making the information available online as is the usual way for 'good' hackers.

Microsoft has admitted that the flaw exists, but does not know of any current attacks in the wild against users of its IE browser.

Although attacks are unlikely we recommend vigilance as always when visiting websites that you don't normally use and considering alternative browsers such as Mozilla until Microsoft release a security patch for this.

[url=\"http://itvibe.com/news/3812/\"][u][Source][/u][/url]