4 ms·
The proof of concept is foiled. But how about something similar like: <noscript> <meta http-equiv="refresh" content="600" url="phish.php"> </nosc
by blauwbilgorgel 12y ago
The proof of concept is foiled. But how about something similar like:
<noscript>
<meta http-equiv="refresh" content="600"
url="phish.php">
</noscript>
- githulhu 12y agoI believe NoScript will pop up a message asking if you want to take the redirect, in that case.
- blauwbilgorgel 12y agoI think you are right: "Forbid META redirections inside <noscript> elements" but then I immediately wondered, what about META redirections outside <noscript> elements? I tested this with a fresh install of Firefox and latest NoScript, and those still work. Also: To forbid meta redirections inside noscript elements you have to toggle an option, it's not standard for non-trusted sites.
- wtallis 12y agoDid you test the META redirection with a background tab? I'm pretty sure NoScript added an unconditional block of background redirects within a week or so of this attack being publicized.