Account Options

  1. Sign in
The old Google Groups will be going away soon.
Switch to the new Google Groups.
Google Groups Home
« Groups Home
Discussions > Troubleshooting > Security : Popups easily imitable
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  1 message - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Shift  
View profile  
 More options Sep 4 2008, 5:22 pm
From: Shift
Date: Thu, 4 Sep 2008 14:22:40 -0700 (PDT)
Local: Thurs, Sep 4 2008 5:22 pm
Subject: Security : Popups easily imitable
Hi,

I have installed Google Chrome at work to test it 'cause at home I use
linux. In my firm, the web access is done throw a proxy server so when
I launched Chrome, a popup was opened in the tab to ask me my login
and password for this proxy server.

But there is something that surprised me : The popup stay on the page
as f it was a DHTML popup. It can't even go over the border of the
page. It's cool but it is a big security hole 'cause it is very easy
to imitate this popup for a web developer with DHTML. Nothing in the
real popup can make me thing that it comes from the browser and not
the website.

It is a very important security hole ! Websites can use this to
retrieve my login and password.

What do you think about that ?

Franck


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »