Collected research
Hijacking Safari 4 Top Sites with Phish Bombs
CVE-2009-2196: a page could script a hidden, blurred window to visit chosen sites repeatedly until Safari 4's Top Sites panel replaced the victim's real thumbnails with attacker pages. Combined with the CSS history hack to pick which banks to imitate, it gives persistent phishing that survives the browsing session. Fixed in Safari 4.0.3.
Record
- Researcher
- Inferno
- Published by
- securethoughts.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Inferno, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .