New Security Threat Involving Pop Ups
Posted: Fri Dec 10, 2004 2:07 pm
"Net security firm Secunia has discovered a way to use pop-up windows to fool even cautious users into thinking they are on an official site when in fact they are giving information to a phisher.
What happens is that a user clicks on a link in an e-mail or on a web page, and their browser opens up the real site, a bank or auction house, say.
But at the same time an invisible window onto a malicious site is opened. Then if the legitimate site opens a pop-up window, as many do, the malicious site is able to hijack it and write whatever it wants onto the screen.
This could be a link to another part of the malicious site or even a form asking for login details."
What happens is that a user clicks on a link in an e-mail or on a web page, and their browser opens up the real site, a bank or auction house, say.
But at the same time an invisible window onto a malicious site is opened. Then if the legitimate site opens a pop-up window, as many do, the malicious site is able to hijack it and write whatever it wants onto the screen.
This could be a link to another part of the malicious site or even a form asking for login details."