My Diigo Bits 11/22/2006
November 23, 2006mozilla links - Mozilla news, tips and more. » Severe Firefox vulnerability uncovered Annotated(3)
- HDD2006’s Remarks : Opera Wand Rocks ,还是Opera安全,Wand密码管理对这种欺骗免疫,这段时间用Fx2.0和Flock老是无法存一些网站的PW,比如抓虾,Netvibes etc,很不爽,改用Ai roboform才搞定,现在Fx2.0这个bug要命的,没有更新的update前,安全的方法是禁用记忆密码功能。不知道roboform有没有影响?因为也有个扩展。 - post by hdd2006
However if you prefer to stay in the safe side of this issue, you better disallow password saving in Firefox:
- In the Tools menu, select Options…
- In the Security page, uncheck Remember passwords for sites
Internet Explorer 7 doesn’t automatically fills the fake form in the test case, but lists the credentials as if it was the real one.
Opera 9.02 Wand, its password management tool, correctly differentiates them and doesn’t autofill the fake form.
“It’s foolish to think it’s only occurring on MySpace.”
“It’s probably happening now and we just don’t know about it,”
Solidot | Firefox 2.0密码管理Bug会泄露密码
- 有点无法忍受的bug,just from my POV. - post by hdd2006




