* Posts by Drew Masters

2 publicly visible posts • joined 25 May 2007

Firefox spoofing bug raises phishing fears

Drew Masters
Alert

Sanitisation???

I think the issue is that:

"Google Account (https://www.google.com)'' Certified by Verisign: blahblah click ''Certificate"

is a VALID realm! ( I think...)

Firefox SHOULDN'T sanitise this... Although FF could display things a little better to make it clear which site you're giving details to.

But imho FF hasn't really got a security bug; more of a layout/clarity issue.

:)

Strange spoofing technique evades anti-phishing filters

Drew Masters

Malware

This looks suspiciously like malware, Torpig for example displays that exact page for hsbc...