This has been possible for sometime now. Guninski originally showed that =
this could be possible here:

http://www.guninski.com/popspoof.html

Date: 21 October 2001=20

Image moving over download/open dialog:=20
http://www.guninski.com/opf2.html=20
BSOD emulation:=20
http://www.guninski.com/bsod1.html=20

All of these [above and below] works on IE 6, full patches, w2k3.

> -----Original Message-----
> From: Andrew Clover [mailto:and-bugtraq@doxdesk.com]=20
> Sent: Sunday, July 13, 2003 12:20 PM
> To: bugtraq@securityfocus.com
> Subject: IE chromeless window vulnerabilities
>=20
>=20
> Title: IE chromeless window vulnerabilities
> Affects: Internet Explorer 5.5 and later
> Risk: Medium
>=20
>=20
> Introduction
> ------------
>=20
> A window without a frame, title bar, toolbars or scroll bars=20
> is known as a 'chromeless' window. If a chromeless window can=20
> be opened on top of other windows, it is possible to=20
> impersonate Windows user interface elements.
>=20
> Why is this a security problem? Because Windows and browser=20
> UI elements are themselves part of security mechanisms. If=20
> the UI for security features can be faked, users can be=20
> tricked into making inappropriate decisions.
>=20
> The 'traditional' way of doing chromeless windows was to use=20
> the DHTML method window.open to open a full-screen browser=20
> window (which is
> chromeless) and then resize this to smaller dimensions. This=20
> capability was removed in IE6 Service Pack 1, presumably due=20
> to exactly these security concerns.
>=20
>=20
> The problem
> -----------
>=20
> It is still possible to get chromeless windows by using the=20
> window.createPopup method. A window opened with createPopup=20
> has some unusual properties:
>=20
> - It is closed when one clicks on the outside the popup.=20
> This is easy
> to circumvent by simply re-spawning it on close.
>=20
> - It cannot be focused. (It is impossible to put controls like text
> input fields in it; this, at least, prevents us from overlaying
> fake login forms onto other websites.) Focus stays with the opener
> window.
>=20
> - It floats above other normal windows, allowing it to obscure them
> even whilst they are focused.
>=20
> One popup may be created per window, allowing one to overlay=20
> an arbitrary rectangle of screen display area with fake UI.=20
> More complicated overlays can be achieved by having multiple=20
> windows opening popups at once; a popup is itself a window so=20
> can be used to open further popups.
>=20
>=20
> Exploitation
> ------------
>=20
> There are three simple exploit demonstrations at:
>=20

http://www.doxdesk.com/personal/post...q/20030713-ie/

One fakes the address bar to seem to be another site; another tries to =
trick the user into adding a bookmark to the favorites menu
by hiding the dialog box that has focus; another hides an ActiveX =
download prompt in order to fool the user into allowing arbitrary
code to be run. These exploits are unpolished and could no doubt be made =
more convincing and robust, but this demonstrates the risk.


Solution
--------

window.createPopup() should have the same chromeless window restrictions =
as
createModalDialog() and createModelessDialog().


Workaround
----------

Disable Active Scripting.


Vendor response
---------------

Microsoft were informed of the problem on 23rd January. After initially =
encouraging e-mails, no action has been taken since.

I am posting this issue now as I have seen it being exploited in the =
wild.

If you use IE, be extremely wary of trusting what appear to be its =
built-in security controls.

--=20
Andrew Clover
mailto:and@doxdesk.com
http://www.doxdesk.com/