Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror

Comment Re:The article doesn't describe the actual exploit (Score 0) 232

"cURL" out to those sites?
Sir, if we had the credentials needed to send a cURL request with your cookies (to see if you were logged in), you've already been hijacked. (cURL requests are server-side.)

The vulnerability comes more from the fact that some browsers let JavaScript "see" what the URL of another window is.

Oh, that, and many people won't notice that the URL isn't form their bank.

Funny, though. A modern pop up blocker will stop this 9/10 times (unless you do the infamous body.onclick trick).

Slashdot Top Deals

Swap read error. You lose your mind.

Working...