{"id":49,"date":"2003-12-11T21:27:24","date_gmt":"2003-12-11T21:27:24","guid":{"rendered":""},"modified":"2003-12-11T21:27:24","modified_gmt":"2003-12-11T21:27:24","slug":"","status":"publish","type":"post","link":"https:\/\/www.sungate.co.uk\/?p=49","title":{"rendered":"Danger, Will Robinson!"},"content":{"rendered":"<p>And we have yet another major security hole in <a href=\"http:\/\/www.microsoft.com\/windows\/ie\/default.asp\">Microsoft Internet Explorer<\/a>.  And this one&#8217;s fairly easy to understand and almost as easy to exploit, which is bad news for anyone who uses IE.<\/p>\n<p>Basically, IE can fool the user into thinking that it is showing Site A, when in fact it is showing Site B.  Click <a href=\"http:\/\/equinox.vm.bytemark.co.uk\/bug.html\">here<\/a> for my specially-prepared demonstration.  Note that this demonstration is safe and does not in itself constitute a security risk, it merely demonstrates the problem.  But then again, why should you trust <i>me<\/i>?<\/p>\n<p>This bug is not good.  For example: You see a link that looks like your online banking service, you click on it and it looks like the right web site and has the correct address in the address bar.  Except it&#8217;s actually something else &#8211; someone trying to con you into leaving sensitive information (such as usernames and passwords or other personal data).<\/p>\n<p>For a technical description of how the bug can be exploited, see the advisory from the Danish security company <a href=\"http:\/\/www.secunia.com\/advisories\/10395\/\">Secunia<\/a>.  Given that I created the test exploit in about half a minute, it doesn&#8217;t take a rocket scientist to figure out that this bug could give rise to a lot of problems.<\/p>\n<p>Oh, and Microsoft are <a href=\"http:\/\/www.pcworld.com\/news\/article\/0,aid,113831,00.asp\">investigating<\/a>.  But seriously, folks, don&#8217;t you think it&#8217;s time you installed <a href=\"http:\/\/www.mozilla.org\/products\/firebird\/\">something better<\/a> now?  Yes??<\/p>\n","protected":false},"excerpt":{"rendered":"<p>And we have yet another major security hole in Microsoft Internet Explorer. And this one&#8217;s fairly easy to understand and almost as easy to exploit, which is bad news for anyone who uses IE. Basically, IE can fool the user into thinking that it is showing Site A, when in fact it is showing Site&#8230;&nbsp;(<a href=\"https:\/\/www.sungate.co.uk\/?p=49\">read more<\/a>)<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-49","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/49","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=49"}],"version-history":[{"count":0,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/49\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=49"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=49"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=49"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}