MS: Ability to Co-opt Pop-ups a 'Design Consideration'

By Scott M. Fulton, III | Published October 31, 2006, 12:01 PM

The ability for a Web page to wrest control of the source of content for a pop-up browser window that appears beside it, is not a design flaw or vulnerability in Internet Explorer 7, as security services firm Secunia stated yesterday, but instead "an important design consideration...to provide a consistent customer experience," according to a statement from Microsoft security spokesperson Christopher Budd.

"Because Microsoft had previously determined that this actually isn't a security vulnerability," Budd writes, "there has been some confusion over these new reports." Browsers, he said, are designed with the capability for pages to pop up windows beside them, and direct them to reload their content from specific sources.

"This is actually an important design consideration for many Web sites, especially line-of-business sites, that re-use windows to provide a consistent customer experience," reads Budd's statement. "However, an example of how this could be used to mislead users would be for an untrusted site to pop up a browser window over a trusted site. To make this compelling, the pop-up window would be created without an address bar. The combination of these events could then be used to add untrusted content to legitimate looking pop-up windows in a phishing or spoofing attack."

Yesterday, Secunia posted a security advisory alerting users to what it claimed to be a vulnerability affecting IE7. If two browser windows are open, and the second one generates a pop-up window, the first is capable of directing content to that window. Secunia posted a link to a test enabling users to discover the vulnerability for themselves.

As Secunia's window wrested control of a pop-up generated by USAToday.com, its message to users read, "This page could easily have contained malicious information spoofed as being from USA Today, asking you to install programs or disclose sensitive information such as credit card details."

Microsoft, Budd writes, started wrestling with this issue in 2004. At that time, Budd said, Microsoft decided that for a malicious site to misrepresent a page in this way, the pop-up window would have to hide its address bar, so that the user would not be able to specifically see that the content comes from a different site.

"We found that in all cases," he posts, "for this to represent a threat for phishing or spoofing attacks, a user would have to decide to trust the authenticity of the page without verifying the page's address (because there was no address bar) and without verifying an SSL connection."

In his company's response to Microsoft, Secunia CTO Thomas Kristensen states that six browser manufacturers, including Firefox, Netscape, and Opera, all addressed the same co-opting capability in 2004 and released a fix for it. But as BetaNews discovered in its own test yesterday, the vulnerability continues to impact Firefox versions 1.5 and 2.0, as well as IE6; and that at least one installation of IE7 we've witnessed is immune to the vulnerability, for reasons we're still working to discover.

Also, with regard to the vulnerable IE7 installation we tested, we noted the URL of the content which wrests control of USAToday's pop-up in the Secunia test, does show prominently at the top of the window.

Still, as Kristensen counter-argued for his company blog today, "If this 'functionality' is required, then the setting to allow this dangerous interaction between different windows and pop-ups can easily be enabled on a per-site basis, or for sites which are trusted. We believe that Microsoft ought to take responsibility for the bugs, weaknesses, and vulnerabilities in their browser, to ensure that it really protects against phishing and similar scam attacks." Kristensen makes no claim of the vulnerability's effectiveness in competitive browsers.

Comments

View comments by with a score of at least

Heh...and how long has ms been saying, "It's not a bug. It's a Feature!"--a couple of decades?

Score: 0

|

Another reason for me to continue using Firefox.

Score: 0

|

spin rating: 9.2

Score: 0

|

Flame away all you want--ActiveX is not a bug of IE because it can be used for malicious purposes, just as Co-opt Pop-ups are not bugs. It seems logical and sane to me, although I'm sure there will be a deluge of replies from those who believe otherwise.

Don't expect any replies. I may give them if I feel the need (hint: use intelligent arguments and not POV arguements), but don't expect them. There is no reason for me to argue with those who are unwilling to be open minded and objective.

Score: 0

|

Every time Micro$oft uses the two words "customer experience" I start to get nervous :)

Score: 0

|

My favorite is "customer preference." as if the customer is specifically asking for a failure in software design and Microsoft *must* comply.

Score: 0

|

as if the customer is specifically asking for a failure in software design and Microsoft *must* comply.
You think this never happens in software development?

Score: 0

|

"customer preference" can mean 1 customer. It can also mean an employee that is also a customer. :)

Score: 0

|

Reminiscent of the infamous "Its not a bug, its an undocumented feature"...

Score: 0

|

Only, this time, it is a feature.

The chances of successfully exploiting this "security hole" are slim, at the very most.

Score: 0

|

Report: Microsoft to randomize Europe's browser screen choices

The fact that "A" is for "Apple" was apparently at the heart of browser vendor objections to Microsoft's alternative to listing IE first.

Acer eclipses Dell for #2 spot in global PC shipments, says iSuppli data

It literally does look like a 360-degree turnaround in Dell's fortunes, as the bells of bad tidings now toll solely for Dell.

Microsoft, don't hang up on Windows Mobile, but do call for help

Only a Manhattan Project can save Microsoft's phone strategy now.

See ya later, WinMo: Microsoft's mobile strategy needs a reboot

Carmi Levy | Wide Angle Zoom: Hands up if you're considering upgrading to a Windows phone for the holidays...Anybody?

Will Nokia's plans further alienate American consumers?

A look at Nokia's plans for the coming years does little to shine up the company's increasingly dull image.

Bing bonked by service outage Thursday, Microsoft configured the wrong server

It's always nice to have a backup, but it's even nicer to remember which one is the backup. That's the lesson Bing's admins learned yesterday evening.

Survey reveals there are more women then men, including on social networks

If you think you can market your products and services online as though you're selling car batteries in the middle of halftime, think again. And again.

Android team updates 'Donut' and 'Eclair' SDKs

The Android SDK includes components which optimize app development for each version of the mobile operating system. Today, the 1.6 and 2.0 components got updates.

The Black Screen Syndrome, or, Tech news in search of the apocalypse

Scott Fulton On Point: This is a story about something that should not have been a story, about something that at one time was a story.

Online advertising evolves away from display, toward interactive software

Marketing departments and agencies are increasingly establishing positions for "creative technologists" who can steer designers and developers toward platforms that enable direct connections with consumers.

Comcast deal for NBC Universal is about content, not broadband

Although Comcast is certainly America's largest broadband provider, at least for PCs, in most regards, today's deal with GE may not impact the Internet at all.