Bodhi -> RE: Warning MAJOR Scam (10/14/2004 1:25:58 PM)
|
Don't know why, I'm pretty sure Secunia are a bona fide Danish IT security firm. The test is just a page with a link showing as www.microsoft.com, and the URL contains a %00 after the www.microsoft.com (and a non-printing character to blank the rest of the line), after which comes the real URL, the Secunia page URL again. If your browser is vulnerable, you'll see www.microsoft.com both in the status bar if you hover over the link, and also in the address bar if you click the link. Maybe your IT desk looks for the classic spoofing "%00" in the address? BTW, I've just tested it in a version of IE with the latest patches and it seems to display the full URL when you hover over the link and page not found on click. There is another javascript test on the site where you can get www.yahoo.com in the address bar, but a Secunia page displayed. This one's a bit more obvious though as you get the yahoo page displayed for a short time before the Secunia page. The first problem was around for ages before MS finally fixed it, I just wonder how many people aren't aware of it and don't have updated versions of MS IE.
|
|
|
|