11.28.06
Watch your passwords
According to president of Chaplin Information Services - users of both Mozilla’s Firefox and Microsoft’s Internet Explorer are at risk of having their saved passwords stolen. Users of social networking services, and visitors to forums and blogging services are most at risk, because pages at these types of sites can be modified using HTML code to make them look like login pages to the browser’s password manager. Iteresting is that the URLs of such pages look legitimate. The risk arises because the password manager of each browser can be tricked into handing over saved passwords to fake login pages.
Firefox and MySpace in the case checks to see if the login form is coming from the official MySpace.com domain. Unfortunatly they does`t check that the password information is being sent back to MySpace.
Not everyone agrees that it’s the actual browsers that are at fault. Some people leveled the blame squarely at social networking services flaw due to insufficient sanitizing. Both Microsoft and Mozilla have been notified about security vulnerability, and at the time of writing Mozilla had at least recognized the problem.
Viewed 271 times by 155 viewers

















