Results 1 to 2 of 2

Thread: Firefox, IE Vulnerable To Fake Login Pages?

  1. #1
    Join Date
    Aug 2006
    Location
    Orlando FL
    Age
    70
    Posts
    1,316

    Firefox, IE Vulnerable To Fake Login Pages?

    Dubbed a reverse cross-site request, or RCSR, vulnerability by its discoverer, Robert Chapin, the flaw lets hackers compromise users' passwords and usernames by presenting them with a fake login form. Firefox Password Manager will automatically enter any saved passwords and usernames into the form.

    The data is then automatically sent to an attacker's computer without the user's knowledge, according to the Chapin Information Services site.

    An exploit for this flaw has already been seen on social-networking site MySpace.com, and it could affect anyone using a blog or forum that allows user-generated HTML code to be added, according to Chapin.

    News.Com

  2. #2
    Join Date
    Nov 2006
    Location
    Hawaii
    Posts
    13
    I would hardly consider this a flaw or exploit. This has been around since forever.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •