Jump to content

Internet Explorer bug leaks whatever you type in the Address Bar

AlTech

IE has a bug where whatever you type into the address bar is leaked.

 

ie-address-bar-leak.jpg

 

The flaw has been discovered and will probably be fixed in the upcoming October Cumulative Update for Windows 10 and as a Cumulative Update for Windows 8.1. No idea about Windows 7 though since that doesn't come with IE11 as Standard as of Service Pack 1.

 

Quote

There's a bug in the latest version of Internet Explorer that leaks the addresses, search terms, or any other text typed into the address bar.

The bug allows any currently visited website to view any text entered into the address bar as soon as the user hits enter. The technique can expose sensitive information a user didn't intend to be viewed by remote websites, including the Web address the user is about to visit. The hack can also expose search queries, since IE allows them to be typed into the address bar and then retrieved from Bing or other search services.

 

And Microsoft has reacted to the situation:

Quote

Windows has a customer commitment to investigate reported security issues, and proactively update impacted devices as soon as possible. Our standard policy is to provide solutions via our current Update Tuesday schedule

 

My grandma is running IE11. I tried to get her to use Edge but she wouldn't listen...... Hopefully she'll move to Chrome or Firefox cos of all the nonsense with security issues.

 

Anyhow, this isn't the first and won't be the last IE11 Vulnerability. If you are an IE11 diehard user then you'll need to find a different browser :D.

 

Source:

https://arstechnica.co.uk/information-technology/2017/09/bug-in-fully-patched-internet-explorer-leaks-text-in-address-bar/

 

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

Can we agree that businesses like HSBC and hospitals need to move away from IE6 and IE11 to a real browser for secure things? Pretty please? -_-

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, AluminiumTech said:

Can we agree that businesses like HSBC and hospitals need to move away from IE6 and IE11 to a real browser for secure things? Pretty please?

But ... but ... but everyone uses Internet Explorer!  It's the standard upon which the web is built!  You really want people to use a non-standard browser for important stuff such as banking? 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Captain Chaos said:

But ... but ... but everyone uses Internet Explorer!  It's the standard upon which the web is built!  You really want people to use a non-standard browser for important stuff such as banking? 

IE is as much of a Standard as FireFox or Chrome imho. We need to convince companies to stop important transactions happening through IE.

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Captain Chaos said:

We need to stop anything happening through IE.  The only thing IE ever was good for was to install Windows Updates on XP and to download a real browser. 

On windows 8.1 touch it was the best browser due to a metro interface until Firefox managed to get the virtual keyboard working properly on the desktop.

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, Captain Chaos said:

We need to stop anything happening through IE.  The only thing IE ever was good for was to install Windows Updates on XP and to download a real browser. 

Oh god no.. not even. What a disaster that was.. even downloading another web browser.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, L.Lawliet said:

What is IE?

Internet Explorer. An older browser family that has a bad reputation even though few releases were actually bad for thier time.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

Considering on even my Windows 98SE desktops I get out my 2001 PC World disc and install Opera off it since IE crashes a lot with HTML documents and websites in general.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

Saw that article a few days ago. Was hoping someone would make a topic on it, so it can go on the wan show. No one did... 

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, AluminiumTech said:


My grandma is running IE11. I tried to get her to use Edge but she wouldn't listen...... Hopefully she'll move to Chrome or Firefox cos of all the nonsense with security issues.

 

Hey put her on FF57 and customize it to look like IE (you can make it look a lot like IE now ty square tabs) and set the homepage to whatever IE defaults as.

Then change the icon to the explorer icon

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Sypran said:

Hey put her on FF57 and customize it to look like IE (you can make it look a lot like IE now ty square tabs) and set the homepage to whatever IE defaults as.

Then change the icon to the explorer icon

No. I'm not that kind of person.

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, NumLock21 said:

Saw that article a few days ago. Was hoping someone would make a topic on it, so it can go on the wan show. No one did... 

I only saw it today. had I seen it earlier I would have made an article earlier.

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

16 hours ago, AluminiumTech said:

Can we agree that businesses like HSBC and hospitals need to move away from IE6 and IE11 to a real browser for secure things? Pretty please? -_-

I remember logging in to our social security services few years ago and it asked me to use Internet Explorer. Good thing the three banks I bank with doesn’t give a damn on what browser I used and they’ve replaced Flash animations to modern web standards back in 2011. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, hey_yo_ said:

I remember logging in to our social security services few years ago and it asked me to use Internet Explorer. Good thing the three banks I bank with doesn’t give a damn on what browser I used and they’ve replaced Flash animations to modern web standards back in 2011. 

No no. I'm talking about how HSBC uses IE11 to access customer data and setup stuff.

 

I'm not saying they're forcing anybody to use it. I'm saying they're using it to access important data.

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

I'm sorry if I sound terrible noob as for right now but... provided you don't bing search your credit card information or your passwords, breaching the keywords the user was trying to search doesn't exactly seem that much of a harmful security issue?

Personal Desktop":

CPU: Intel Core i7 10700K @5ghz |~| Cooling: bq! Dark Rock Pro 4 |~| MOBO: Gigabyte Z490UD ATX|~| RAM: 16gb DDR4 3333mhzCL16 G.Skill Trident Z |~| GPU: RX 6900XT Sapphire Nitro+ |~| PSU: Corsair TX650M 80Plus Gold |~| Boot:  SSD WD Green M.2 2280 240GB |~| Storage: 1x3TB HDD 7200rpm Seagate Barracuda + SanDisk Ultra 3D 1TB |~| Case: Fractal Design Meshify C Mini |~| Display: Toshiba UL7A 4K/60hz |~| OS: Windows 10 Pro.

Luna, the temporary Desktop:

CPU: AMD R9 7950XT  |~| Cooling: bq! Dark Rock 4 Pro |~| MOBO: Gigabyte Aorus Master |~| RAM: 32G Kingston HyperX |~| GPU: AMD Radeon RX 7900XTX (Reference) |~| PSU: Corsair HX1000 80+ Platinum |~| Windows Boot Drive: 2x 512GB (1TB total) Plextor SATA SSD (RAID0 volume) |~| Linux Boot Drive: 500GB Kingston A2000 |~| Storage: 4TB WD Black HDD |~| Case: Cooler Master Silencio S600 |~| Display 1 (leftmost): Eizo (unknown model) 1920x1080 IPS @ 60Hz|~| Display 2 (center): BenQ ZOWIE XL2540 1920x1080 TN @ 240Hz |~| Display 3 (rightmost): Wacom Cintiq Pro 24 3840x2160 IPS @ 60Hz 10-bit |~| OS: Windows 10 Pro (games / art) + Linux (distro: NixOS; programming and daily driver)
Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Princess Cadence said:

I'm sorry if I sound terrible noob as for right now but... provided you don't bing search your credit card information or your passwords, breaching the keywords the user was trying to search doesn't exactly seem that much of a harmful security issue?

For the few everyday users that aren't naive about safe browsing, it isn't an issue. For companies that use IE for internal database access, it's a real threat.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

23 minutes ago, Princess Cadence said:

I'm sorry if I sound terrible noob as for right now but... provided you don't bing search your credit card information or your passwords, breaching the keywords the user was trying to search doesn't exactly seem that much of a harmful security issue?

The problem I see if causing is the sites that contain your account number or any specific information in the URL. Overall its not that big of an issue but in specific cases it can cause a problem.

Link to comment
Share on other sites

Link to post
Share on other sites

22 hours ago, AluminiumTech said:

IE is as much of a Standard as FireFox or Chrome imho. We need to convince companies to stop important transactions happening through IE.

 

22 hours ago, Captain Chaos said:

But ... but ... but everyone uses Internet Explorer!  It's the standard upon which the web is built!  You really want people to use a non-standard browser for important stuff such as banking? 

It is anything but a standard.  Pretty much any other browser implements modern web standards better than it.  Just ask any web dev

 

---

 

I remember webpages doing this for ages, and I don't recall in what browser but I think in things besides IE... you would search google and then go to one of the links and it would be another search based on your terms.

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×