<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Nasty new IE hole</title>
	<link>http://www.metafilter.com/30123/Nasty-new-IE-hole/</link>
	<description>Comments on MetaFilter post Nasty new IE hole</description>
	<pubDate>Tue, 09 Dec 2003 14:29:58 -0800</pubDate>
	<lastBuildDate>Tue, 09 Dec 2003 14:29:58 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Nasty new IE hole</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole</link>	
		<description>&lt;a href="http://www.zapthedingbat.com/security/ex01/vun1.htm"&gt;A new MS Internet Explorer vulnerability is discovered.&lt;/a&gt; Most digerati already know about the spammer and lamer trick to publish URLs that look like legitimate hostnames to fool people in to trusting a malicious site.  This trick is frequently used by spammers to steal people&apos;s PayPal accounts, by tricking them in to &quot;resetting&quot; their password at a site owned by the spammer but disguised as PayPal.com.

Today&apos;s new IE vulnerability is significantly worse. By including an 0x01 character after the @ symbol in the fake URL, IE can be tricked in to not displaying the rest of the URL at all. Don&apos;t expect a patch right way, the guy who found the hole &lt;a href=&quot;http://www.securityfocus.com/archive/1/346948&quot;&gt;released it to BugTraq on the same day&lt;/a&gt; he notified Microsoft. &lt;small&gt; (via &lt;a href=&quot;http://simon.incutio.com/&quot;&gt;Simon Willison&lt;/a&gt;)&lt;/small&gt;</description>
		<guid isPermaLink="false">post:www.metafilter.com,2003:site.30123</guid>
		<pubDate>Tue, 09 Dec 2003 14:28:08 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>		<category>computers</category>		<category>internet</category>		<category>software</category>		<category>browsers</category>		<category>security</category>		<category>IE</category>		<category>internetexplorer</category>
	</item>	<item>
		<title>By: dejah420</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598471</link>	
		<description>d&apos;oh! right *away*.  Sigh.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598471</guid>
		<pubDate>Tue, 09 Dec 2003 14:29:58 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>
	</item>	<item>
		<title>By: boltman</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598472</link>	
		<description>Thank God for Mozilla</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598472</guid>
		<pubDate>Tue, 09 Dec 2003 14:33:12 -0800</pubDate>
		<dc:creator>boltman</dc:creator>
	</item>	<item>
		<title>By: RylandDotNet</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598473</link>	
		<description>&lt;i&gt;Don&apos;t expect a patch &lt;strike&gt;right away&lt;/strike&gt;&lt;/i&gt; ever.

They may do a service pack, but then again they may not. I don&apos;t think this bug is any more critical than any of the other many, many bugs that aren&apos;t going to get patched. Isn&apos;t this supposed the final release of a stand-alone IE browser?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598473</guid>
		<pubDate>Tue, 09 Dec 2003 14:33:16 -0800</pubDate>
		<dc:creator>RylandDotNet</dc:creator>
	</item>	<item>
		<title>By: dejah420</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598477</link>	
		<description>&lt;em&gt;Thank God for Mozilla.&lt;/em&gt;

Agreed.  The complete url is visible using Moz1.6a...can&apos;t speak to any earlier versions.

&lt;em&gt;Isn&apos;t this supposed the final release of a stand-alone IE browser?&lt;/em&gt;

Oh, gods forbid.  *shudder*</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598477</guid>
		<pubDate>Tue, 09 Dec 2003 14:36:03 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>
	</item>	<item>
		<title>By: monju_bosatsu</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598479</link>	
		<description>IE 6 is the last version that will be released before Longhorn comes out, as I understand the situation.  MS has basically said they will not be supporting any browser between now and then.  May I recommend &lt;a href=&quot;http://www.mozilla.org/products/firebird/&quot;&gt;Firebird&lt;/a&gt;?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598479</guid>
		<pubDate>Tue, 09 Dec 2003 14:39:11 -0800</pubDate>
		<dc:creator>monju_bosatsu</dc:creator>
	</item>	<item>
		<title>By: riffola</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598484</link>	
		<description>The test URL: 
http://www.microsoft.com%01@zapthedingbat.com/security/ex01/vun2.htm doesn&apos;t work as intended in IE6 SP1, I see http://zapthedingbat.com/security/ex01/vun2.htm in the address bar instead of http://www.microsoft.com</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598484</guid>
		<pubDate>Tue, 09 Dec 2003 14:47:51 -0800</pubDate>
		<dc:creator>riffola</dc:creator>
	</item>	<item>
		<title>By: costas</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598497</link>	
		<description>MS will still support (and presumably improve, but I have my doubts) the IE engine which will just be a part of the OS. Conspiracy theories aside, putting the HTML renderer into the OS makes perfect sense these days --and it&apos;s the same route that OSX, KDE and to a lesser extent Gnome are going.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598497</guid>
		<pubDate>Tue, 09 Dec 2003 15:03:28 -0800</pubDate>
		<dc:creator>costas</dc:creator>
	</item>	<item>
		<title>By: dejah420</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598502</link>	
		<description>Riff...weird.  Using IE 6.0.28, sp1, when I click the button, it takes me to a page that purports to be microsoft.com.  I wonder if you installed an update that I didn&apos;t which blocks the hole...or if I installed one that you didn&apos;t that opened it.  Hmmmm...now I&apos;ll have to go turn on other computers and check various versions.  Perhaps do a clean, non patched install, and test it with each patch to see if I can nail down where the hole gets opened...or perhaps closed.  

If you get a chance, could you email me your configuration, and I&apos;ll see if I can get some other coders working on why you don&apos;t have the hole...perhaps we can find a way to patch it for everyone, and we won&apos;t have to wait for MS to do something.  Also, I&apos;m just really curious...and I love taking things apart just so I can put them together again. ;)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598502</guid>
		<pubDate>Tue, 09 Dec 2003 15:09:05 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>
	</item>	<item>
		<title>By: Nauip</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598516</link>	
		<description>By including an 0x01 character &lt;strong&gt;after&lt;/strong&gt; the @ symbol in the fake URL</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598516</guid>
		<pubDate>Tue, 09 Dec 2003 15:26:45 -0800</pubDate>
		<dc:creator>Nauip</dc:creator>
	</item>	<item>
		<title>By: mr_crash_davis</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598518</link>	
		<description>Also, note that in the string &quot;location.href=unescape(&apos;url&apos;)&quot;, &lt;b&gt;unescape&lt;/b&gt; is key.  Without it, the exploit does not work.

Copy the source code yourself to a file on your desktop and try it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598518</guid>
		<pubDate>Tue, 09 Dec 2003 15:29:23 -0800</pubDate>
		<dc:creator>mr_crash_davis</dc:creator>
	</item>	<item>
		<title>By: emelenjr</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598520</link>	
		<description>Safari predictably does nothing with that Test button, and Mac IE 5.2 shows
http://www.microsoft.com%01@zapthedingbat.com/security/ex01/vun2.htm 
in the address bar. It&apos;s clear I&apos;m not looking at a Microsoft.com page. The exploit is not a problem for Mac users, AFAIK.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598520</guid>
		<pubDate>Tue, 09 Dec 2003 15:31:47 -0800</pubDate>
		<dc:creator>emelenjr</dc:creator>
	</item>	<item>
		<title>By: phyrewerx</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598532</link>	
		<description>The Title Bar on my IE6.01 actually says: &quot;http://zapthedingbat.com/security/ex01/vun2.htm&quot; for a split second before the test page with the MSFT logo loads.

So on the bright side, if I looked at the Title Bar when ever a web page loads, I&apos;ll be fine right...RIGHT?

&lt;small&gt;(Screw it, I&apos;m switching to firebird)&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598532</guid>
		<pubDate>Tue, 09 Dec 2003 15:56:06 -0800</pubDate>
		<dc:creator>phyrewerx</dc:creator>
	</item>	<item>
		<title>By: tiamat</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598542</link>	
		<description>No effect on Opera 7.2, FYI.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598542</guid>
		<pubDate>Tue, 09 Dec 2003 16:17:35 -0800</pubDate>
		<dc:creator>tiamat</dc:creator>
	</item>	<item>
		<title>By: riffola</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598552</link>	
		<description>I&apos;m using IE 6.0.2800.1106
Update versions: SP1; Q822925; q313829; Q330994; Q828750; Q824145 on 98SE
(Don&apos;t ask, my regular machine running XP died.)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598552</guid>
		<pubDate>Tue, 09 Dec 2003 16:37:10 -0800</pubDate>
		<dc:creator>riffola</dc:creator>
	</item>	<item>
		<title>By: scottandrew</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598556</link>	
		<description>If that exploit page had been more convincingly designed, I would&apos;ve definitely been fooled.

That said, how exactly could you use this? Since the unescape() is needed, that would require JavaScript. And to hide the JavaScript, you&apos;d need to put it in an HTML link or form element and hope the victim&apos;s email client supports HTML mail. Otherwise the victim would see all that &quot;javascript:&quot; stuff.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598556</guid>
		<pubDate>Tue, 09 Dec 2003 16:45:44 -0800</pubDate>
		<dc:creator>scottandrew</dc:creator>
	</item>	<item>
		<title>By: ph00dz</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598586</link>	
		<description>I hate it that people don&apos;t wait... I mean... come on. This is gonna be the biggest pain in the ass. At least IE is pretty straightforward to patch with the updater now, so it could be worse...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598586</guid>
		<pubDate>Tue, 09 Dec 2003 18:15:26 -0800</pubDate>
		<dc:creator>ph00dz</dc:creator>
	</item>	<item>
		<title>By: piper28</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598596</link>	
		<description>Course, even if they fix it, you&apos;d have to wait till the end of a monthly cycle for them to release the fix.  Only Microsoft would come up with a policy of only releasing patches monthly when they get criticized for too many patches.  I&apos;d rather see more patches in a timely manner than fewer patches delayed who knows how long.

Course, the real way not to get nailed with this is not to be an idiot and blindly follow links.  If you&apos;re stupid enough to blindly fall for some of these attempts to get your passwords in the first place, then odds are you aren&apos;t looking at the address anyways.

(For the record, works exactly as described on my xp machine).</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598596</guid>
		<pubDate>Tue, 09 Dec 2003 18:31:42 -0800</pubDate>
		<dc:creator>piper28</dc:creator>
	</item>	<item>
		<title>By: Eloquence</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598619</link>	
		<description>Wait for fake &quot;Donate via Paypal&quot; buttons to pop up all over the net.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598619</guid>
		<pubDate>Tue, 09 Dec 2003 19:22:53 -0800</pubDate>
		<dc:creator>Eloquence</dc:creator>
	</item>	<item>
		<title>By: kjh</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598669</link>	
		<description>right-click, properties on the target page shows the accurate url. (oh, and of course, all legitimate paypal pages are https. double-click on the lock icon to verify.)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598669</guid>
		<pubDate>Tue, 09 Dec 2003 21:09:30 -0800</pubDate>
		<dc:creator>kjh</dc:creator>
	</item>	<item>
		<title>By: drezdn</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598700</link>	
		<description>&lt;i&gt;Course, the real way not to get nailed with this is not to be an idiot and blindly follow links. If you&apos;re stupid enough to blindly fall for some of these attempts to get your passwords in the first place, then odds are you aren&apos;t looking at the address anyways.&lt;/i&gt;

I agree with you for the most part, but will admit that I&apos;ve fallen for an email scam once... I got an email that supposedly came from ebay and it was really a password harvester.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598700</guid>
		<pubDate>Tue, 09 Dec 2003 22:43:18 -0800</pubDate>
		<dc:creator>drezdn</dc:creator>
	</item>	<item>
		<title>By: dinsdale</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598719</link>	
		<description>this is a great example of the general trend for the &apos;bad guys&apos; to simply bypass security systems.  Sort of analogous to &apos;social engineering&apos; tactics like phoning someone up, pretending to be a tech support person, and asking them for their password.

See &lt;a href=&quot;http://www.iang.org/ssl/maginot_web.html&quot;&gt;The Maginot Web&lt;/a&gt;

&lt;i&gt;&quot;What a sad state of affairs.  The CA-signed certificate, far from being the key to browsing security, is the Maginot Line that preserves the masses in a state of blissful ignorance. 

&quot;It works perfectly against the attacks conceived and theorised as the dramatic threat to mankind, commerce and the Internet, a decade ago.  Problem is, the attackers bypassed it, with as much disdain as any invading army against the last war&apos;s dug-in defence. 

&quot;Problem is, the security model had unreasonable expectations.  Problem is, the users didn&apos;t subscribe to their part of the protocol.  (To be fair, it&apos;s hard to communicate to users that they are even expected to be part of anything.) 

&quot;Problem is, the browser manufacturers that were sold on the need for the certs also got sold on the convenience of click and launch.  So, they turned around and sold the security model down the river faster than one can say &quot;check the URL...&quot;&lt;/i&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598719</guid>
		<pubDate>Tue, 09 Dec 2003 23:58:43 -0800</pubDate>
		<dc:creator>dinsdale</dc:creator>
	</item>	<item>
		<title>By: quonsar</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598728</link>	
		<description>&lt;a href=&quot;http://news.com.com/2008-1082_3-5065859.html?tag=lh&quot;&gt;cough&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598728</guid>
		<pubDate>Wed, 10 Dec 2003 00:21:35 -0800</pubDate>
		<dc:creator>quonsar</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598740</link>	
		<description>If you&apos;re switching to Firebird, there&apos;s a&lt;a href=&quot;http://seb.mozdev.org/firebird&amp;e=1102&quot;&gt; windows installer out there&lt;/a&gt; that makes installing plug-ins and such much eaiser.

For some reason mozdez.org is down right now.

Of course Mozilla comes with its own installer and the&lt;a href=&quot;http://www.mozilla.org/releases/#1.6b&quot;&gt; beta of 1.6 just came out.&lt;/a&gt;

Also, the &lt;a href=&quot;http://www.mozilla.org/projects/thunderbird/release-notes.html&quot;&gt;Mozilla Thunderbird&lt;/a&gt; email client just hit version .4, I&apos;m assuming the vector for this attack will be through email.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598740</guid>
		<pubDate>Wed, 10 Dec 2003 01:44:06 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: bwerdmuller</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598759</link>	
		<description>I&apos;m a Firebird user, but use MSIE for development purposes. I note that this exploit fools the Google Toolbar (a test page I set up claiming to be whitehouse.gov got a pagerank of 10), so this could have very nasty implications for people foolish enough to set software to automatically fill in usernames and passwords. Like, for example, the Google Toolbar. Does anyone know if it fools MSIE&apos;s own auto-password functions?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598759</guid>
		<pubDate>Wed, 10 Dec 2003 03:40:57 -0800</pubDate>
		<dc:creator>bwerdmuller</dc:creator>
	</item>	<item>
		<title>By: Blue Stone</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598784</link>	
		<description>I notice that if you use the Avant IE6 browser interface, the url is shown to be bogus. 
The only difference between it and Mozilla, is that Avant shows a vertical bar, in bold, as opposed to the %01 before the &quot;@&quot;.
I don&apos;t know about the other IE6 modification browsers out there, but perhaps they&apos;re all worth checking out if you&apos;re attatched to IE6 [god have mercy on your soul.]</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598784</guid>
		<pubDate>Wed, 10 Dec 2003 05:45:49 -0800</pubDate>
		<dc:creator>Blue Stone</dc:creator>
	</item>	<item>
		<title>By: oissubke</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598795</link>	
		<description>I love my Avant browser.  It took me a second to realize that the reason I was seeing the URL correctly was because I wasn&apos;t using IE....</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598795</guid>
		<pubDate>Wed, 10 Dec 2003 06:09:42 -0800</pubDate>
		<dc:creator>oissubke</dc:creator>
	</item>	<item>
		<title>By: nicwolff</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#598821</link>	
		<description>kjh, this trick would work just fine under HTTPS, since the browser doesn&apos;t know it&apos;s not showing the actual hostname. The lock icon will appear, so unless the user is in the habit of double-clicking it to verify every HTTPS page, they will think they&apos;re seeing a secure page from Paypal.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-598821</guid>
		<pubDate>Wed, 10 Dec 2003 07:00:52 -0800</pubDate>
		<dc:creator>nicwolff</dc:creator>
	</item>	<item>
		<title>By: Tlogmer</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#599171</link>	
		<description>A bigger problem is MS&apos;s braindead decision to have the status bar hidden by default.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-599171</guid>
		<pubDate>Wed, 10 Dec 2003 18:56:40 -0800</pubDate>
		<dc:creator>Tlogmer</dc:creator>
	</item>	<item>
		<title>By: yerfatma</title>
		<link>http://www.metafilter.com/30123/Nasty-new-IE-hole#599813</link>	
		<description>Looks like Mozilla is &lt;a href=&quot;http://www.mozillazine.org/talkback.html?article=4078&quot;&gt;partially vulnerable too.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2003:site.30123-599813</guid>
		<pubDate>Fri, 12 Dec 2003 06:14:49 -0800</pubDate>
		<dc:creator>yerfatma</dc:creator>
	</item>
	</channel>
</rss>
