Friday, January 09, 2004

Microsoft Internet Explorer Domain URL Spoofing

A relatively new vulnerability which was originally reported as far back as December 9, 2003, allows a malicious person to create web sites that look exactly like the real one with a 'spoofed' web addresses to match. When a user visits one of these spoofed sites, the URL in the address bar of IE it will look as if they're at real site.

Unfortunately, Microsoft still has not released a patch for this exploit. So, to avoid being taken by this scam, below are two tricks that can help you:

Trick 1: If you go to a web site or page, and you want to verify its real URL address of it just, add the following shortcut to your browser's favorites. Right-click the following link, and select 'Add to Favorites'.

All you have to do is click the shortcut in the browser after visiting a web page, and it will show you the real address of the web site.

Trick 2: Below are two non-Microsoft patches that can be installed to prevent this problem:
- I.E. Security Patch
- DomainSpoofFilter

No comments: