Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Firefox: about:blank is phisher's best friend Feb 16 2007 10:50PM
Michal Zalewski (lcamtuf dione ids pl) (2 replies)
Re: Firefox: about:blank is phisher's best friend Feb 22 2007 08:27PM
Florian Weimer (fw deneb enyo de) (1 replies)
Re: Firefox: about:blank is phisher's best friend Feb 22 2007 08:56PM
Michal Zalewski (lcamtuf dione ids pl)
On Thu, 22 Feb 2007, Florian Weimer wrote:

> This is the first time I read about the forced window title change. I
> hadn't noticed it earlier. Do you think this is a good enough security
> indicator (or indicator of origin, to be more precise)?

This is quite inadequate as far as protecting inexperienced users is
considered - but at least offers a chance for more alert ones to notice
the problem.

Bypassing it through about:blank elliminates even this opportunity, so
we're back in square one...

/mz

[ reply ]
RE: Firefox: about:blank is phisher's best friend Feb 19 2007 03:52PM
Michael Wojcik (Michael Wojcik microfocus com)







 

Privacy Statement
Copyright 2008, SecurityFocus