2 ms·
Thanks! Minor nitpicks: this would fail if the login page were itself on HTTPS (as most login pages should be). Also, Hotmail no longer exists.
by seldo 13y ago
Thanks! Minor nitpicks: this would fail if the login page were itself on HTTPS (as most login pages should be). Also, Hotmail no longer exists.
- peterwwillis 13y agoHotmail was a joke :) But almost all browsers try HTTP before they try HTTPS, which is where the attack commonly comes in (or you intercept their primary request, or sslstrip, etc). Exceptions are if they're Chrome and have a whitelisted set of URLs, or support HSTS, or explicitly specified by the user or a bookmark. The point is, the attack is there and it works, even if it doesn't work in 100% of cases.