Collecting the weird and wonderful
techy stories from in and around the interweb.
The great Firefox browser has a bit of a flaw in terms of how it manages it password manager. The password manager will check the domain inwhich the <form> came from, but does not check where the form is going to be submitted to.
So, for blogging sites (MySpace etc) then you can easily upload an HTML page/form, and then start harvesting username/passwords from people that you can trick into giving you their details.
tags: firefox password attack
links: digg this del.icio.us technorati reddit
Sign-up to the mailing list to be alerted when a new news entry goes online.

SpikeSource tests, certifies, and supports open source software. We make open source more safe and reliable for enterprise use.

This work is licensed under a
Creative Commons License.
