|
|
| |
| Firefox, if allowed, can store usernames and passwords. If you visit a login page again, the password is then entered automatically. But this means, that a second, evil page on the same server could steal those saved passwords. |
| |
Credit:
The information has been provided by carl hardwick.
The original article can be found at: http://www.heise-security.co.uk/services/browsercheck/demos/moz/pass1.shtml?name=noam&password=noampassword#
|
| |
Vulnerable Systems:
* Firefox version 2.0.0.5 and prior
The method Firefox uses to autocomplete fields allows attackers sitting on the same site (http://www.mysite.com/mypage) as that were you have stored your web site (http://www.mysite.com/myotherpage) to capture the password stored in the Firefox's password storage mechanism.
|
|
|
|
|
|
|
|