![]() |
![]() |
![]() |
![]() |
![]() |
Information about your favorite browser: news, articles and more.
Spoofing vulnerability in Firefox
Published March 23rd, 2007 in Browser Security, Exploits & Vulnerabilities, Firefox
A design error in the Firefox browser can allow phishers to conceal the true origins of a web page
from the user. This could be used to place extremely deceptively genuine looking web pages from organisations such as banks, eBay, PayPal and other providers on the web (spoofing). Browser security specialist Michal Zalewski has provided a demonstration web page to enable interested users to understand the problem. The demo works with Firefox 1.5 and 2.0.
According to Zalewski, the problem lies in the way Firefox deals with the URL about:blank, which opens a blank page. The browser does not show either a URL in the address bar or information in the window’s title bar. heise Security - News - Spoofing vulnerability in Firefox








