firefox (and other) form vulnerability

| | Comments (1)

Looks like there is a vulnerability in various browsers where you type data into one form but the data really gets sent to another window. An exploit to demo it is at Secunia's website and uses citibank as the form that you would fill in. It doesn't take a genius to work the potential of this exploit - however in this particular demonstration the keystrokes do not appear on the form so some people might get a bit suspicious, but then judging from the people who get infected by the latest virus's there are a lot of not very suspicious people out there in internet land.

1 Comments

It's fixed in Firefox 1.0 RC2. When a web page shows a dialog or a message, Fx switches to the tab that originated the message.

Categories

Pages

Powered by Movable Type 4.1

About this Entry

This page contains a single entry by published on October 31, 2004 6:19 PM.

Internet Mail Service account is no longer valid was the previous entry in this blog.

Toshiba laptop back - and broken again. is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.