WebApp Sec mailing list archives

Re: Article - A solution to phishing


From: mike () sharecube com
Date: 15 Jul 2005 00:23:55 -0000

The acutrust.com security blanket isn’t particularly safe. First, it requires revealing your password. Therefore, it 
means that you have to type your password to some potentially rogue site before you know if it is valid.

Both this and PassMark like sites can be bypassed with fairly simple HTML and Javascript. See shameless plug: 
http://www.sharecube.com/shared-secret-exploits.html).

By the way: It isn’t slow as in another post. It does nothing until you type your entire password.


Mike Podanoffsky (CTO)
www.sharecube.com


Current thread: