Forgot your password?
typodupeerror

Comment Re:The article doesn't describe the actual exploit (Score 0) 232

"cURL" out to those sites?
Sir, if we had the credentials needed to send a cURL request with your cookies (to see if you were logged in), you've already been hijacked. (cURL requests are server-side.)

The vulnerability comes more from the fact that some browsers let JavaScript "see" what the URL of another window is.

Oh, that, and many people won't notice that the URL isn't form their bank.

Funny, though. A modern pop up blocker will stop this 9/10 times (unless you do the infamous body.onclick trick).

Slashdot Top Deals

"A great many people think they are thinking when they are merely rearranging their prejudices." -- William James

Working...