Internet content spoofing scam
Internet content spoofing scam
R E L A T E D   C O N T E N T
ADVERTISEMENT

Microsoft flaw leaves PCs open to phishing

ISA Server 2000 and Proxy Server 2.0 affected by internet spoofing scam

Robert Jaques, vnunet.com 10 Nov 2004
ADVERTISEMENT

Microsoft has warned users of a serious vulnerability in ISA Server 2000 and Proxy Server 2.0 products that could allow malicious hackers to execute internet content spoofing scams.

According to alert MS04-039, the flaw could be used by cyber-criminals to carry out phishing attacks to trick unwary users into disclosing passwords and sensitive financial information.

"This is a spoofing vulnerability that exists in the affected products that could enable an attacker to spoof trusted internet content," Microsoft warned.

"Users could believe they are accessing trusted internet content when in reality they are accessing malicious internet content, for example a malicious website.

"However, an attacker would first have to persuade a user to visit the attacker's site to attempt to exploit this vulnerability."

Software affected by the vulnerability includes Microsoft Proxy Server 2.0 Service Pack 1, Microsoft Internet Security and Acceleration Server 2000 Service Pack 1 and Microsoft Internet Security and Acceleration Server 2000 Service Pack 2.

Microsoft Small Business Server 2000 (which includes Microsoft Internet Security and Acceleration Server 2000) and Microsoft Small Business Server 2003 Premium Edition are also affected.

As a workaround Microsoft advised users of the affected products to set the DNS cache size to zero.

"Setting the DNS cache size to zero effectively disables DNS caching on the affected system. This would prevent the affected software from using potentially spoofed data from the cache. This may have negative performance impact on DNS resolution," Microsoft said.

The software giant added that, if a customer suspects that their system has been affected by attempts to exploit this vulnerability, clearing the web proxy cache will help remove the suspected malicious content.

Full information and details of the fix are available here.

See also:

Email masquerades as official software updateBank suspend elements of its online service to protect customers  17 Nov 2004
Survey reveals a high percentage of firms feel vulnerable to IT security attacks  15 Nov 2004
Trojan targets UK online banksBanker-AJ Trojan sends passwords and screenshots to remote hackers  11 Nov 2004
Social engineeringStudy reveals junk mail tactics becoming ever more sophisticated  10 Nov 2004
New phishing techniqueJust open an email and you could be the next victim, warns security firm  04 Nov 2004
Trojan53 people arrested in Brazil for online banking fraud  21 Oct 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities