Web Hack List

Other nomination

Cross Domain Basic Auth Phishing Tactics

Basic-auth phishing needs no clicked link: an embedded image on a protected domain pops the credential dialog on the page you want to phish. Alex supplies two dialog-spoofing bugs that hide the real host: Opera truncates the hostname after 34 characters and appends an ellipsis, and IE7 shows the Punycode form, so a Cyrillic o in microsoft.de passes.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.