Advertisement
Home
Saturday, 22 November 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  8778  71.58%
Win 2003  1950  15.90%
Win 2000  722  5.89%
Solaris 9/10  402  3.28%
FreeBSD  226  1.84%
Other  185  1.51%

Total attacks: 12263 of which 4619 single ip and 7644 mass defacements

Polls
Should Zone-H continue mirroring defacements? (floods will be purged)
 
Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
ZONE-H In Numbers
 News: 14559
 Advisories: 11
 Managers: 1
 Administrators: 1
 Super Administrators: 3
 Operators: 3
 Registered Users: 38290
 Downloadable Files: 3888
 Digital Attacks: 2981160
 Attacks On Hold: 3080
 Online Users: 78
Syndicate
Visitors' Map
Highlight on most recent attacks
jiefanglu.gov.cn/zkn.txt by ZoRRoKiN       ytjj.gov.cn/zkn.txt by ZoRRoKiN       bislig.gov.ph by Ashiyane Digital Security Team       prefeiturajoseraydan.com.br by Fatal Error       semag.taquarussu.ms.gov.br by Fatal Error       pmsaltodolontra.com.br by Fatal Error       cmirituia.com.br by Fatal Error       pmriobrancodoivai.com.br by Fatal Error       prefeituraborrazopolis.com.br by Fatal Error       pmcurionopolis.com.br by Fatal Error       
Latest advisories
Latest on Digital Warfare
Latest on Geopolitics
Microsoft leaves an open door to phishers! PDF Print E-mail
User Rating: / 12
PoorBest 
Wednesday, 11 April 2007

phishing2Cyber Criminals often appeal to users' unawareness and good faith to design their attacks, and in spite of constant information made by journals, blogs, magazines and IT Security organizations, this phenomenon, and specially the number of victims, keeps growing.

But what happens when a site considered as trusted, actually contains a “trap” for the user?

On this proposal, a “trap” has been discovered by Zone-H on MSN Video site, where it is possible to force the site through a crafted URL to display a web-page reporting the following message:

This product requires Microsoft Internet Explorer 6 with Microsoft Media Player 10 and Macromedia Flash 6, or Mozilla Firefox 1.5 with Macromedia Flash 8, or Safari 2.0.4 with Macromedia Flash 8. To download these free software applications, click the links below and follow the on-screen instructions”..

The Link Below”, whose the above text is referring to, can be set up (eventually coded in hexadecimal) by the attacker using the crafted URL .


 

msn_phishing2



































Similar situations represent a tricky risk for Internet users, since they could allow phisher and cyber criminals to build their attacks. Such attacks are particularly effective because they are based on the trusted relationship “User->Trusted Site”, since unaware users generally judge the authenticity of a web site on the basis of the address displayed on the address-bar.

But this is not the only problem affecting MSN, indeed, after further analyses we have discovered a Cross-Site Scripting vulnerability in the italian shopping section of MSN web site In this specific case, it's easy to realize that the scope of malicious actions depends just on the attacker’s bravery.

 

msn_shopping_xss




































While waiting for Microsoft (already informed about the vulnerability) to fix the problems, we suggest to mitigate risks (for example when you have to do with e-mail, forum, chat, Instant Messagin, etc..) by using “ant-XSS” extension for own browser , and to check the content of the whole URL before clicking on it.

Indeed, links used as vectors for attack against websites affected by XSS and similar vulnerabilities, have a known pattern: almost in all cases, a part of the URL contains HTML tags like <script>, </script>, <img xsrc=javascript:..", which can be also “obfuscated” in hexadecimal (for example the tag “<script>” become “%3c%73%63%72%69%70%74%3e”) or they could hide other URLs that point to external websites.

 

 


Comments Index (Total Messages: 2)
MSN vulnerabilities Written by Guest on 2007-04-12 15:58:31
  xx Written by kabus on 2007-04-12 18:14:26

Powered by a Zone-H(ified) version of AkoComment 3.0!


DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The   author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice.
 
< Prev   Next >
Advertisement
 
Top! Top!