[28340] in bugtraq

home help back first fref pref prev next nref lref last post

Re: CITIBANK [CANADA]: INTERNET EXPLORER BROWSERS

daemon@ATHENA.MIT.EDU (Ben Laurie)
Tue Dec 31 09:53:26 2002

Message-ID: <3E10BF01.8070002@algroup.co.uk>
Date: Mon, 30 Dec 2002 21:47:45 +0000
From: Ben Laurie <ben@algroup.co.uk>
MIME-Version: 1.0
To: http-equiv@malware.com
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

http-equiv@excite.com wrote:
> Sunday, December 29, 2002
> 
> There is a small silly hitch with CITIBANK CANADA's secured sign in 
> to online banking:
> 
> https://citibankcanada.ebilling.com/index.jhtml
> 
> Specifically AUTOCOMPLETE="off" in the forms. It is not set.
> 
> While much explanation is made about SSL connections and fancy 
> digital certificates, the simplest of web programming errors 
> Thwarte ! all that:
> 
> CITIBANK CANADA's login allows for the Microsoft Internet Explorer 
> autocomplete feature to function. What that does is remember your 
> name and password. So on a public or even private machine, all one 
> needs to do is, double click the "name" form and the password will 
> automicrosoftly autocomplete [fill in].

This is, of course, a fault in IE, not Citibank.

Cheers,

Ben.

-- 
http://www.apache-ssl.org/ben.html       http://www.thebunker.net/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff


home help back first fref pref prev next nref lref last post