Internet Explorer 7
A new vulnerability in Internet Explorer 7 could be exploited by identity thieves

New IE7 bug exposes users to content injection

Software 'feature' could allow ID theft

Written by Tom Sanders in California

Security researchers at Secunia have discovered a new vulnerability in Internet Explorer 7 that could be exploited by online identity thieves. 

An attacker could inject content into another website's window, for instance replacing a log-in pop-up window for an online bank with a page that looks similar to the bank's log-in window.

The attacker would have to know the target name of the window being replaced, and would require the attacker's website and the target website to be open at the same time.

Secunia rated the vulnerability as 'moderately critical', its third most severe security rating on a five-step scale.

A Microsoft spokesman denied that the reported flaw describes a vulnerability in its software.

The company told vnunet.com in an emailed statement that Secunia describes the issue as "a by-design behaviour in popular web browsers that allows a website to open or reuse a pop-up window".

Users will be able to tell that they have been directed to a phishing website because the pop-up window displays an address bar.

Secunia issued a warning about a similar vulnerability in Internet Explorer 5 and 6 in 2004. 

Today's alert is the fourth alleged security vulnerability that Secunia has unearthed in Internet Explorer 7 since the browser was launched earlier this month.

In addition to today's denial, Microsoft has dismissed one other Secunia report because it affected Outlook Express rather than IE7. Microsoft has confirmed the two other vulnerabilities.

Tags:

reader comments

related articles

 

Microsoft pushes out 17 security fixes

'Critical' patches for Windows, Office and Internet Explorer 13 Feb 2008

Paypal to block older browsers

Plans to improve security include banning outdated browsers 18 Apr 2008

New Firefox browser blocks hacked websites

Makers say that surfers are "safer with Firefox than with any other browser" 07 Mar 2008

related whitepapers

today's top stories

IT's stock is soaring at the LSE

London Stock Exchange IT chief David Lester explains to Angelica Mari how the integration of Borsa Italiana is keeping his team busy, despite the worsening economy 20 Nov 2008

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Has the state of the economy forced to re-evaluate your IT purchasing options?

Has the state of the economy forced to re-evaluate your IT purchasing options?

Are you re-thinking your IT spending?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

Dave BaileyComment

Clouds darken outlook for Vista's successor

Windows 7 looks like being an improvement on Vista, but economic and environmental concerns may mean few enterprises will rush to adopt it 20 Nov 2008

Soca unitAnalysis

EU police in the dock over data sharing

Poor integration and lax practices are jeopardising EU efforts to fight international crime 20 Nov 2008

Advertisement

Primary Navigation