[Full-disclosure] Firefox: about:blank is phisher's best friend

2007-03-10 Thread Michal Zalewski
Firefox suffers from a design flaw that can be used to confuse casual users and evoke a false sense of authority when visiting a fraudulent website. The flaw can be also used to bypass a fix for an old UI spoofing bug that was thought to be addressed. This is a relatively minor issue, but I

Re: [Full-disclosure] Firefox: about:blank is phisher's best friend

2007-02-22 Thread Michal Zalewski
On Thu, 22 Feb 2007, Florian Weimer wrote: This is the first time I read about the forced window title change. I hadn't noticed it earlier. Do you think this is a good enough security indicator (or indicator of origin, to be more precise)? This is quite inadequate as far as protecting

Re: [Full-disclosure] Firefox: about:blank is phisher's best friend

2007-02-19 Thread Michael Wojcik
From: Michal Zalewski [mailto:[EMAIL PROTECTED] Sent: Friday, 16 February, 2007 17:51 To: bugtraq@securityfocus.com Cc: full-disclosure@lists.grok.org.uk Firefox suffers from a design flaw that can be used to confuse casual users and evoke a false sense of authority when visiting a