ceagle: (Default)
ceagle ([personal profile] ceagle) wrote2004-10-25 04:11 am

most internet browsers seem vulnerable

to this security problem I just saw posted. :/
Go here to test yours if you like: http://secunia.com/multiple_browsers_dialog_box_spoofing_test/

(this one will really blow your mind, [livejournal.com profile] makovette)

be careful out there folks... and happy (safe) surfing to ya :>

[identity profile] makovette.livejournal.com 2004-10-25 04:28 am (UTC)(link)
Yeah, it go 'splodey! FF and other 'zilla based browsers have this problem with their html parsers.

Fun fun fun...

Hopefully FF 1.0 will fix the problem, which will get pushed back into the rest of 'zilla browsers.

CYa!
MAko

[identity profile] ekevoo.livejournal.com 2004-10-25 05:22 am (UTC)(link)
I'm on FF 1.0 Preview Release. :(

=ekevu=, scared 'cuz he hangs a lot on bank websites

[identity profile] stoda.livejournal.com 2004-10-25 07:57 am (UTC)(link)
Narsty. Fails in Opera 7.5, they expect to have it fixed next version.

Yet another example of more power = more vulnerability. There's just WAY too much crap hung off of HTML to make it secure.

[identity profile] genmaicha.livejournal.com 2004-10-25 08:39 am (UTC)(link)
Yeek. That's disturbing.

[identity profile] secret-wolver.livejournal.com 2004-10-25 01:30 pm (UTC)(link)
How is this a security risk? You can make those type windows for your own pages. I've seen it done to welcome visitors.

[identity profile] patchoblack.livejournal.com 2004-10-25 07:10 pm (UTC)(link)
The pop-up window with fields to enter text is suppose to show up after you click on a link to another (presumably secure) site. The idea is that it shows up AFTER the page the link goes to loads up. The pop-up window then can be made to look like it is asking for sensitive information and is coming from said secure site.

[identity profile] secret-wolver.livejournal.com 2004-10-25 10:27 pm (UTC)(link)
Oooh, I can see how some people will fall for that.

[identity profile] c-eagle.livejournal.com 2004-10-27 02:57 am (UTC)(link)
Thanks for the comments, folks... ah hope it's been a helpful thread for yas. *chyrp*