UI Misrepresentation of Critical Information |
Weakness ID: 451 (Weakness Base) | Status: Draft |
Description Summary
Reference | Description |
---|---|
CVE-2001-0398 | Attachment with many spaces in filename bypasses "dangerous content" warning and uses different icon. Likely resultant. |
CVE-2001-0643 | Misrepresentation and equivalence issue. |
CVE-2005-0593 | Lock spoofing from several different Weaknesses. |
CVE-2005-0143 | Wrong status / state notifier -- Lock icon displayed when an insecure page loads a binary file loaded from a trusted site. |
CVE-2005-0144 | Wrong status / state notifier -- Secure "lock" icon is presented for one channel, while an insecure page is being simultaneously loaded in another channel. |
CVE-2004-0761 | Wrong status / state notifier -- Certain redirect sequences cause security lock icon to appear in web browser, even when page is not encrypted. |
CVE-2004-2219 | Wrong status / state notifier -- Spoofing via multi-step attack that causes incorrect information to be displayed in browser address bar. |
CVE-2004-0537 | Overlay -- Wide "favorites" icon can overlay and obscure address bar |
OSVDB:5703 | Overlay -- GUI overlay vulnerability (misrepresentation) |
CVE-2005-2271 | Visual distinction -- Web browsers do not clearly associate a Javascript dialog box with the web page that generated it, allowing spoof of the source of the dialog. "origin validation error" of a sort? |
CVE-2005-2272 | Visual distinction -- Web browsers do not clearly associate a Javascript dialog box with the web page that generated it, allowing spoof of the source of the dialog. "origin validation error" of a sort? |
CVE-2005-2273 | Visual distinction -- Web browsers do not clearly associate a Javascript dialog box with the web page that generated it, allowing spoof of the source of the dialog. "origin validation error" of a sort? |
CVE-2005-2274 | Visual distinction -- Web browsers do not clearly associate a Javascript dialog box with the web page that generated it, allowing spoof of the source of the dialog. "origin validation error" of a sort? |
CVE-2001-1410 | Visual distinction -- Browser allows attackers to create chromeless windows and spoof victim's display using unprotected Javascript method. |
CVE-2002-0197 | Visual distinction -- Chat client allows remote attackers to spoof encrypted, trusted messages with lines that begin with a special sequence, which makes the message appear legitimate. |
CVE-2005-0831 | Visual distinction -- Product allows spoofing names of other users by registering with a username containing hex-encoded characters. |
CVE-2003-1025 | Visual truncation -- Special character in URL causes web browser to truncate the user portion of the "user@domain" URL, hiding real domain in the address bar. |
CVE-2005-0243 | Visual truncation -- Chat client does not display long filenames in file dialog boxes, allowing dangerous extensions via manipulations including (1) many spaces and (2) multiple file extensions. |
CVE-2005-1575 | Visual truncation -- Web browser file download type hiding using whitespace. |
CVE-2004-2530 | Visual truncation -- Visual truncation in chat client using whitespace to hide dangerous file extension. |
CVE-2005-0590 | Visual truncation -- Dialog box in web browser allows user to spoof the hostname via a long "user:pass" sequence in the URL, which appears before the real hostname. |
OSVDB:6009 | Visual truncation -- GUI obfuscation (visual truncation) in web browser - obscure URLs using a large amount of whitespace. Note - "visual truncation" covers a couple variants. |
CVE-2004-145 | Visual truncation -- Null character in URL prevents entire URL from being displayed in web browser. |
CVE-2004-2258 | Miscellaneous -- [step-based attack, GUI] -- Password-protected tab can be bypassed by switching to another tab, then back to original tab. |
CVE-2005-1678 | Miscellaneous -- Dangerous file extensions not displayed. |
CVE-2002-0722 | Miscellaneous -- Web browser allows remote attackers to misrepresent the source of a file in the File Download dialogue box. |
Perform data validation (e.g. syntax, length, etc.) before interpreting the data. |
Create a strategy for presenting information, and plan for how to display unusual characters. |
Overlaps Wheeler's "Semantic Attacks" Here are some examples of misrepresentation: [*] icon manipulation (making a .EXE look like a .GIF) [*] homographs: letters from different character sets/languages that look similar. The use of homographs is effectively a manipulation of a visual equivalence property. [*] a race condition can cause the UI to present the user with "safe" or "trusted" feedback before the product has fully switched context. The race window could be extended indefinitely if the attacker can trigger an error. [*] "Window injection" vulnerabilities (though these are usually resultant from privilege problems) [*] status line modification (e.g. CVE-2004-1104) [*] various other web browser issues. [*] GUI truncation (e.g. filename with dangerous extension not displayed to GUI because of truncation) - CVE-2004-2227 - GUI truncation enables information hiding [*] injected internal spaces (e.g. "filename.txt .exe" - though this overlaps truncation [*] Also consider DNS spoofing problems - can be used for misrepresentation. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 221 | Information Loss or Omission | Research Concepts (primary)1000 |
ChildOf | ![]() | 445 | User Interface Errors | Development Concepts (primary)699 |
PeerOf | ![]() | 346 | Origin Validation Error | Research Concepts1000 |
Misrepresentation problems are frequently studied in web browsers, but there are no known efforts for categorizing these problems in terms of the shortcomings of the interface. In addition, many misrepresentation issues are resultant. |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | UI Misrepresentation of Critical Information |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Potential Mitigations, Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Maintenance Notes, Relationships, Other Notes, Taxonomy Mappings |