4 ms·
You know what, this is a phisher's dream. Even if we could trust this website for not saving the data, the connection is a regular non-secure connection, so all
by ROFISH 16y ago
You know what, this is a phisher's dream. Even if we could trust this website for not saving the data, the connection is a regular non-secure connection, so all somebody would have to do is catch some open wireless connections or similar.
- pquerna 16y agowe have applied for an SSL certificate, from both GoDaddy and Comodo. they are both 'pending', since apparently, having 'credit card' in your domain is suspicious: http://ismycreditcardstolen.com/anti-phishing.jpg http://ismycreditcardstolen.com/anti-phishing.jpg
- rlpb 16y agoI'm not convinced that this will help so much here. Assuming that victims won't be checking for SSL, getting someone to an insecure copy of the site will do. I don't see how this would be your problem, though. Security is a strange beast.
- AngryParsley 16y agoView the HTML source. The credit card inputs aren't part of the form. They're never sent across the wire.
- rlpb 16y agoThis doesn't matter. If the connection is intercepted, the credit card inputs suddenly can be part of the form.
- AngryParsley 16y agoThat's true for any non-https site. They could inject stuff into wellsfargo.com or whatever.
- carbocation 16y agoPerhaps a keylogger's dream, but then I suppose you would have two problems. And regex would not be one of them.
- arnoooooo 16y agoAnother way this could be a good scheme is if people trust it and start sending it as a way to educate people, and when it starts getting momentum, it is changed and does start recording numbers.