ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Story: Microsoft: Stuck between a rock and a hard patch?

  • Previous comment

Posted by: Anonymous (Wednesday 11 February 2004, 4:32 PM)

  • Reply

As a previous responder has noted, this sort of phishing bug only exists on IE on Windows.

I personally use Firefox on Linux and when I try to hit one of these "exploit" sites, the URL shows exactly as it should and reveals that it is not actually the official site. All of my e-commerce sites that legitametly use this feature work fine, ditto to ftp sites that work the same way.

So it is possible to work around this security flaw without breaking anything, just that Microsoft chose not to (I can't believe this didn't realise that they would break sites, that implies even greater incompetence that the most ardent Linux fan will spout)

Of course all this stuff about spoofing URLs is a moot point for a lot of users. How many of your non-techy friends would happily enter their credit card details on such a site even if they saw the URL didn't start with www.microsoft.com ? As one person I spoke to said "well, it has a padlock in the taskbar, so it must be safe"

Yes, Microsoft is without doubt to blame, but phishing attacks will never stop whilst users do not responsibility for their (in)actions.

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread