BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Banks (Wellsfargo.com) using CDNs to deliver Javascript: enables password theft by anyone compromising or controlling the CDN Nov 20 2007 03:39AM
joel peshkin net
In a recent chnage, wellsfargo.com started to include javascript delivered by akamai.net within sensitive pages, such as their login page.

Since any script loaded by the page has access to all the page data, that script could steal passwords very easily. Loading the script via a CDN reduces the ...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus