LWN.net Logo

The Firefox password manager vulnerability

The Firefox password manager vulnerability

Posted Nov 30, 2006 9:13 UTC (Thu) by khim (subscriber, #9252)
In reply to: The Firefox password manager vulnerability by mms
Parent article: The Firefox password manager vulnerability

Previous answer was much better then your long tirada. Have you even read the article ?

The problem happens not when the wrong site shows the form. Problem happens when "trusted" site allow HTML in posts! Then you can put form with TARGET="malicious site" and fqdn or not fqdn - password will be sent to cracker...


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds