[ Sponsored Links ]

Advertise here »

Another phishing technique

 

Sam Greenhalgh has identified a new domain disguising technique to look out for an guard against if you have a sensitive site.

http://www.zapthedingbat.com/security/scriptinjection/ 

The problem is how do you get your own content to display on a screen with barclaysbank as the domain name in the URL.

Easy

Many sites play back your search keys when you do a search. So if you have searched on a bit of javascript that loads your content, then it gets played back and the javascript gets run. 

So if you play back search keys, don’t forget to validate them for HTML tags.

Bob
Textor

 
  • Another phishing technique, textor, 21 Jul 10:26
    Sam Greenhalgh has identified a new domain disguising technique to look out for an guard against if you have a sensitive site. http://www.zapthedingbat.com/security/scriptinject ...
Subscribe for only €299