|
|
| |
|
| |
mozilla-https-everywhere: no SSL switch for some URLs
| Package(s): | mozilla-https-everywhere |
CVE #(s): | |
| Created: | May 3, 2012 |
Updated: | May 9, 2012 |
| Description: |
From the Tor bug entry:
If you go to a URL such as http://www.google.com./ HTTPS-Everywhere will *not* switch to HTTPS. This is a legal DNS value, technically but not practically distinct from http://www.google.com/ and as such, it should be handled similarly.
[...] (it would allow an active attacker to perform Firesheep-style cookie stealing accounts against sites that HTTPS Everywhere protects with domain-wide redirects, if the ruleset does not also have a <securecookie> directive) |
| Alerts: |
|
( Log in to post comments)
|
|
|