Posts Tagged ‘Michal Zalewski’

Vulnerablility discovered in how Firefox handles bookmarks

This item was filled under [ Security, Tech News ]

Michal Zalewski has discovered an interesting vulnerability in how Firefox handles bookmarks.
It is relatively easy to trick a casual user into bookmarking a window that does not point to any physical location, but rather, is an inline data: URL scheme otherwise convincingly pretending to be a “tangible” webpage.
When the bookmark is later clicked, javascript [...]

Continue reading...