Microsoft Internet Explorer 7 HTTP Authentication International Domain Name Spoofing Weakness
BID:24483
Info
Microsoft Internet Explorer 7 HTTP Authentication International Domain Name Spoofing Weakness
| Bugtraq ID: | 24483 |
| Class: | Design Error |
| CVE: |
CVE-2007-3164 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2007 12:00AM |
| Updated: | Jun 15 2007 04:09PM |
| Credit: | Alexander Brachmann discovered this issue. |
| Vulnerable: |
Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 7 HTTP Authentication International Domain Name Spoofing Weakness
Microsoft Internet Explorer 7 is prone to a weakness that may allow attackers to spoof hostnames in HTTP-authentication dialogs.
Attackers may exploit this vulnerability via a malicious webpage to spoof the origin of an HTTP-authentication dialog that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Microsoft Internet Explorer 7 is prone to a weakness that may allow attackers to spoof hostnames in HTTP-authentication dialogs.
Attackers may exploit this vulnerability via a malicious webpage to spoof the origin of an HTTP-authentication dialog that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Exploit / POC
Microsoft Internet Explorer 7 HTTP Authentication International Domain Name Spoofing Weakness
To exploit this issue, an attacker must entice an unsuspecting user to visit a maliciously crafted webpage.
A proof-of-concept page has been created to demonstrate this issue. Please see the references for details.
To exploit this issue, an attacker must entice an unsuspecting user to visit a maliciously crafted webpage.
A proof-of-concept page has been created to demonstrate this issue. Please see the references for details.
Solution / Fix
Microsoft Internet Explorer 7 HTTP Authentication International Domain Name Spoofing Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Microsoft Internet Explorer 7 HTTP Authentication International Domain Name Spoofing Weakness
References:
References:
- Cross Domain Basic Auth Phishing Tactics (ha.ckers)
- Internet Explorer Homepage (Microsoft)
- HTTP-Auth Phishing mit Opera (Alexander Brachmann)