[4016] in WWW Security List Archive
Javascript & Webspoofing.
daemon@ATHENA.MIT.EDU (NightR01@aol.com)
Sun Jan 19 13:43:18 1997
From: NightR01@aol.com
Date: Sun, 19 Jan 1997 11:38:56 -0500 (EST)
To: www-security@ns2.rutgers.edu
Errors-To: owner-www-security@ns2.rutgers.edu
Maybe if there was a specific command in Javascript that was used to
help the attacker in the spoof attack. Then that part of Javascript could be
disabled instead of all of it. If anyone has a script used to spoof a site,
it could be initalized and then a success full way to stop spoofing could be
devised.
Matt Murphy