[LINK] Is Intern Explorer really this accommodating for phishing?

Rick Welykochy rick at praxis.com.au
Fri Feb 9 15:15:30 AEDT 2007


While snooping around the net for PayPal horror stories just now, I cam across
this JPG image of a phishing attempt using Internet Explorer:

http://www.paypalsucks.com/graphics/PayPalSpoofSite1.jpg

Holy crapola, Batman. Does IE really allow Javascript (or some other
mechanism) to change the address control and fool the user even more than I thought?
When I follow a phishing link from email to FireFox, say, the first thing
I notice is that the URL is not the one in the email. FireFox does not seem
to be spoofable w.r.t. the address control.

I would love be corrected on this point, but I think I've just had yet
another insight how bad phishing can be on Winders.

cheers
rickw






-- 
_________________________________
Rick Welykochy || Praxis Services

The religion of one age is the literary entertainment of the next.
      -- Ralph Waldo Emerson



More information about the Link mailing list