Web Hack List

Collected research

Favorites Gone Wild

Watchfire Application Security Insider: Favorites Gone Wild

Yair Amit finds an IE Favorite stored at the root of the tree can be named as a URL, and typing that URL into the address bar then loads the Favorite's target instead. A single planted Favorite gives persistent phishing against users taught to type addresses rather than click links. How to plant it is left as an open question.

Record

Document
Watchfire Application Security Insider: Favorites Gone Wild
Researcher
Yair Amit
Published by
blog.watchfire.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Yair Amit, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .