Weblinx Ltd are a search engine marketing company that structure websites so that they are search engine friendly
| reply to message » | post a new message » | e-mail to a friend » |
| Subject: | Another phishing technique | ||
| Author: | textor: view profile | all posts by this author | add to favourites | ||
| Date: | 10:26:27 21 July 2004 | ||
Sam Greenhalgh has identified a new domain disguising technique to look out for an guard against if you have a sensitive site.
http://www.zapthedingbat.com/security/scriptinjection/
The problem is how do you get your own content to display on a screen with barclaysbank as the domain name in the URL.
Many sites play back your search keys when you do a search. So if you have searched on a bit of javascript that loads your content, then it gets played back and the javascript gets run.
So if you play back search keys, don’t forget to validate them for HTML tags.
Bob
Textor
Another phishing technique, textor, 21 Jul 10:26