Web Hack List

Collected research

Hijacking Safari 4 Top Sites with Phish Bombs

CVE-2009-2196: a page could script a hidden, blurred window to visit chosen sites repeatedly until Safari 4's Top Sites panel replaced the victim's real thumbnails with attacker pages. Combined with the CSS history hack to pick which banks to imitate, it gives persistent phishing that survives the browsing session. Fixed in Safari 4.0.3.

Record

Researcher
Inferno
Published by
securethoughts.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Inferno, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .