Jump to content

Recommended Posts

Posted
Chaplin claims that the attack has already been used to steal the log-in details of MySpace users, who were redirected to a false log-in page where their details were harvested.

I can see this being a big issue since there are quite a few people that don't read links (URLs) before clicking on them.

 

Of course we are talking about MySpace users too. :P

 

Thanks for the info. :)

Posted

When I first read the story I laughed because it's the usual case of a journalist reporting half truths and blowing things out of proportions to sell a story. He seems to inicate that now browsers have phishing alerts people have suddenly forgotten the years of anti phishing advice they have had drummed into them.

 

As to Firefoxs password function going off the domain as opposed to the full url I'd say this was the writers choice as opposed to a flaw.

 

seems to affect all versions of Firefox, and may also affect Microsoft's Internet Explorer.
Chapin has informed Microsoft of the problem.
So the 'problem' definetely exists in Firefox but possibly not in IE so he goes and informs the Microsoft for whom it may not be an issue but apparently does not inform Mozilla?

 

their information can be stolen in this way when visiting blog and forum websites at trusted addresses.

I have yet to see a forum script that would allow this type of HTML to be posted.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...