Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment Re:The article doesn't describe the actual exploit (Score 0) 232

"cURL" out to those sites?
Sir, if we had the credentials needed to send a cURL request with your cookies (to see if you were logged in), you've already been hijacked. (cURL requests are server-side.)

The vulnerability comes more from the fact that some browsers let JavaScript "see" what the URL of another window is.

Oh, that, and many people won't notice that the URL isn't form their bank.

Funny, though. A modern pop up blocker will stop this 9/10 times (unless you do the infamous body.onclick trick).

Slashdot Top Deals

Business is a good game -- lots of competition and minimum of rules. You keep score with money. -- Nolan Bushnell, founder of Atari

Working...