HTTP: Page With Malicious URL Hiding Encoding
This signature detects attempts to exploit a known vulnerability in Microsoft Internet Explorer. Attackers can embed binary control characters in a URL that is included in a Web page; when the URL is viewed, these control characters prevent Internet Explorer from displaying the complete URL, which might have malicious content.
Extended Description
A weakness has been reported in multiple browsers that may allow attackers to obfuscate the URI for a visited page. The problem is said to occur when a URI designed to pass access a specific location with a supplied username, contains a hexadecimal 1 value prior to the @ symbol. An attacker could exploit this issue by supplying a malicious URI pointing to a page designed to mimic that of a trusted site, and tricking a victim who follows a link into believing they are actually at the trusted location.
Affected Products
Microsoft outlook_xp
References
BugTraq: 9182
CVE: CVE-2003-1025
URL: http://www.us-cert.gov/cas/techalerts/TA04-033A.html http://www.kb.cert.org/vuls/id/652278
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Mozilla
Microsoft
Mysoft_studio
4.3