Bugtraq mailing list archives
Re: Firefox: about:blank is phisher's best friend
From: Michal Zalewski <lcamtuf () dione ids pl>
Date: Sat, 17 Feb 2007 22:16:27 +0100 (CET)
On Sat, 17 Feb 2007 zonafirefox () gmail com wrote:
I tested it in IE7 and has the same problem. Opera 9.10 blocks the opening of the new window but fails in the second button.
With MSIE7, it is possible only if you check 'Allow websites to open windows without address or status bar' for that particular zone; otherwise, all windows will have a minimal URL bar attached. I'm not sure whether this setting is default - if it is, yeah, that'd be bad for MSIE. As far as Opera is concerned - by default, Javascript can't hide address bars, and if you change this option, the originating URL is still displayed. /mz
Current thread:
- Firefox: about:blank is phisher's best friend Michal Zalewski (Feb 16)
- RE: Firefox: about:blank is phisher's best friend Michael Wojcik (Feb 20)
- Re: Firefox: about:blank is phisher's best friend Florian Weimer (Feb 22)
- Re: Firefox: about:blank is phisher's best friend Michal Zalewski (Feb 22)
- <Possible follow-ups>
- Re: Firefox: about:blank is phisher's best friend zonafirefox (Feb 17)
- Re: Firefox: about:blank is phisher's best friend Michal Zalewski (Feb 17)