IE/Firefox/Safari phishing exploit found

Security by on October 14, 2004 at 10:56 pm
I’ve been following the anti-phishing market recently (there are few good solutions), and was forwarded an article on a new pop-up exploit that enables a malicious site to take advantage of any ‘friendly’ popups on a bank’s website.

Check out this demonstration of the exploit on Citibank’s website:

There will always be either technical (keyloggers, browser expoits, etc) or social engineered solutions to nab people’s login information. You can’t stop phishing by protecting users from themselves, you need to stop it at the bank’s website.

