On Monday 29 November 2004 18:57, Shaul Karl wrote:
>   The btl (national insurance) is advertising its new online payment
> service. The URL is https://b2b.btl.gov.il/b2b/pay.asp. Is it expected
> to work with non IE?
>   With Konqueror 3.2.2 (Using KDE 3.2.3) from Debian testing, I can see
> the combination of letters that should be entered as a security measure.
> However the Confirmation button seems to have no effect.

If you want some more fun, just browse this frame source and
look for the pearls of wisdom hiding below (currently commented
out, so they point to future "enhanced" version of the page):

"××××× ×××, ×××× ××××× ×××××××× ××××××× 
××××× ××××× ××× ××× ×××××× ××××××××"
"××× ××××××× ×××××× ×××× ×××××× ××××××××× 
×××× ××"

[Dear user, to prevent viruses and exploits to log your
keystrokes we advise you to use the virtual keyboard in
this field]

They seem to mystically believe that their future point'n'click
interface would challenge keyloggers installed on the client.
"... the keyboard was an easy capture, but the mouse events
are beyond us, we surrender..."

I think their next suggestion may be that we all fill our
forms in the "Bet language" (ROT-1)... gee, this must be
hard to figure out...

Who would teach these morons that a compromised client is
a compromised client:

"Dear user, to prevent viruses and malware, please install
 a better browser and consider using an operating system
 with improved security record."

-- 
Oron Peled                             Voice/Fax: +972-4-8228492
[EMAIL PROTECTED]                  http://www.actcom.co.il/~oron
ICQ UIN: 16527398

There's nothing wrong with Windows 2000...
                                       ...that Linux can't fix

=================================================================
To unsubscribe, send mail to [EMAIL PROTECTED] with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail [EMAIL PROTECTED]

Reply via email to