[vox-tech] New phishing vulnerability

Bill Kendrick vox-tech@lists.lugod.org
Fri, 12 Dec 2003 02:35:01 -0800


On Fri, Dec 12, 2003 at 10:20:30AM +0000, Rob Rogers wrote:
> 
> POC
> http://wizardstower.net/ie.html

Heh, Konqueror seems to be okay :)

Hover over the 'click me' link, and I see:

  http://www.paypal.com@wizardstower.net

In the status bar.


Click the link, and I see the following in the URL field at the top:

  http://www.paypal.com@wizardstower.net/


I don't feel like booting up the iMac and installing Safari.
It's based on Konq tho, so it seems /likely/ it won't be affected, either.

*Whew!*

-bill!
bill@newbreedsoftware.com                           Got kids?  Get Tux Paint! 
http://newbreedsoftware.com/bill/       http://newbreedsoftware.com/tuxpaint/