Phish The Master Password In Firefox.

Hacker Halted 2010

703
vote

I always felt that security cannot be simplified. It stands in the way of usability because it requires alertness and a clear mind. While I was busy with the previous example I thought about Firefox master password. I tested this feature and I saw that it only asked me a simple Javascript prompt to enter it.Well we can copy this stuff fairly easy by making our own prompt. I think the trick is to time when you want to throw it at a surfer. Again, this could be used in corporation with Jeremiah Grossman's hack that checks if users are logged into a website or not, like GMail for instance, or plenty of other things. Just fun stuff.

Trackback URL for this post:

http://secgeeks.com/trackback/544