Re: [Full-disclosure] Firefox bookmark cross-domain surfing vuln

看板Bugtraq作者時間19年前 (2007/02/24 01:40), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
pdp (architect) wrote: > However, here is an interesting thought for you: instead of asking the > user into bookmarking a page you can supply the bookmark directly to > their browser by using Live Bookmarks. So, a mainstream attack will be > when a SPLOG network injects malicious links into their feeds. If > someone happens to be subscribed to this network with a Live Bookmark > and they click on it... well you know. > > I haven't tested this, although it should work. It doesn't work -- thankfully we thought of that back when we implemented Live Bookmarks in Firefox 1.0
文章代碼(AID): #15toS000 (Bugtraq)