Re: [Full-disclosure] Firefox bookmark cross-domain surfing

看板Bugtraq作者時間19年前 (2007/02/23 05:04), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
On Thu, 22 Feb 2007, pdp (architect) wrote: > This vulnerability is cute but not very useful mainly because a lot of > social engineering is required. Well, very little trickery is required - having a person bookmark an interesting page and then reopen it later on, while the browser is still on its start page (or just about any other high-profile site), isn't that unusual, and does not rely on an improbable set of circumstances, or the user being particularly timid. This problem is not that significant for a different reason - to affect a small percentage of population, you'd need to invest some serious effort into providing content and PR for the attack site. Spending several days to steal GMail cookies from 1000 users is a waste of time when you can get 10000 rooted boxes in hours with a trojan horse e-mail. So, yeah. /mz
文章代碼(AID): #15tWLt00 (Bugtraq)
文章代碼(AID): #15tWLt00 (Bugtraq)