Re: Firefox: about:blank is phisher's best friend

看板Bugtraq作者時間19年前 (2007/02/23 06:11), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/5 (看更多)
* Michal Zalewski: > Similarly, he could spoof a native browser-originating modal warning or > dialog to have the user do something dumb. This problem was addressed by > forcibly prepending current site name to window title for all URL-bar-less > windows, so that the Internet origin of such a pop-up is clear, and so > that it will have a hard time mimicking a native window. This is the first time I read about the forced window title change. I hadn't noticed it earlier. Do you think this is a good enough security indicator (or indicator of origin, to be more precise)?
文章代碼(AID): #15tXK300 (Bugtraq)
文章代碼(AID): #15tXK300 (Bugtraq)