Hands-On Confirmation of Browser Dialog Origin Vulnerability in Safari 2.0, Firefox 1.0.4, Opera 8.0.1 and Internet Explorer 5.2.3

Secunia posted a new security vulnerabilty for multiple web browsers:

Secunia Research has discovered a vulnerability in various browsers, which can be exploited by malicious web sites to spoof dialog boxes.

The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site.

Secunia posted a test to demonstrate the vulnerability. We ran the test with Safari 2.0, Firefox 1.0.4, Opera 8.0.1 and Internet Explorer 5.2.3. All four displayed the "malicious" javascript data entry window "Test security survey from Google. Please enter a test "password" string:" without stating that it is actually from Secunia. At least Opera displayed "www.google.com.secunia.com" in the window which provides a hint that the window is not from Google.

Secunia's Web page provides suggestions on how to deal with the vulnerability until the web browsers are updated. [Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive