Tuesday, February 24, 2004

URL Spoofing vulnerability (12/19/03)

Patrick Crispen's invaluable Internet Tourbus warns that "If you use Internet Explorer, Microsoft Outlook Express, or Microsoft Outlook, you're vulnerable to something called "URL Spoofing." Is this earth-shattering? No. Should you lose sleep over it? No. Should you at least know a little about it in order to protect your personal information should something strange happen? ABSOLUTELY!"

According to Microsoft, "a malicious user could create a link to a deceptive (spoofed) Web site that displays the address, or URL, to a legitimate Web site in the Status bar, Address bar, and Title bar."

Why is this a bad thing? Well, InformationWeek warns that "This flaw would make it appear to Internet users that they're visiting a banking Web site, for example, when that site is actually a front for fraudsters attempting to collect sensitive financial information..."

How can you tell if you're vulnerable? Just hop on over to Patrick's URL Spoofing site and take his simple test. You might be startled, as you humble editor was.

No comments: