<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Don&#x27;t trust the Lock icon either! in </title>
<link>http://www.dslreports.com/forum/r8751690</link>
<description></description>
<language>en</language>
<pubDate>Mon, 13 Oct 2008 04:55:41 EDT</pubDate>
<lastBuildDate>Mon, 13 Oct 2008 04:55:41 EDT</lastBuildDate>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,9237893</link>
<description><![CDATA[<A HREF="/useremail/u/929001"><b>ephilipps</b></A> : ViruScan Enterprise pops a window just by opening the forum post.  I guess Microsoft will get around to this soomer or later....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9237893</guid>
<pubDate>Fri, 30 Jan 2004 16:02:45 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8910506</link>
<description><![CDATA[<A HREF="/useremail/u/739919"><b>HalfFull</b></A> :  <BLOCKQUOTE><SMALL>said by  The Way Out <A HREF="/useremail/u/756452"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Want to see something scary?  Try this link:<br><br><A HREF="https://www.paypal.com@secure.divo.net/notpaypal/">https://www.paypal.com</A><br><br>It says PayPal in the URL, but it's not paypal!  You'll notice that it still displays the "Lock" in the bottom right hand corner, too.  Be afraid.  :|<br> <HR></BLOCKQUOTE><br><br>sad...since Micro$oft is to cheap to fix the flaw, legitimate businesses will be hurt as the security problem  is more publicized.  Computer-challenged people won't buy on-line because they will be afraid of a scam... ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8910506</guid>
<pubDate>Sun, 28 Dec 2003 16:03:51 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8884933</link>
<description><![CDATA[<A HREF="/useremail/u/917937"><b>jbone_99</b></A> : I actually blocked the link from showing up using ad blocker in norton IS ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8884933</guid>
<pubDate>Wed, 24 Dec 2003 23:19:05 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8792561</link>
<description><![CDATA[<A HREF="/useremail/u/408935"><b>mod bait</b></A> :  <br>/extreme_sarcasm<br><br>Well, hopefully, Microsoft will give this matter several weeks or months of careful consideration and analysis, as they seem to be with the recently-announced active scripting exploits.<br> <br><SMALL>--<br>"Security is a tax on the honest."  --Bruce Schneier, <A HREF="http://www.amazon.com/exec/obidos/tg/detail/-/0387026207"><I>Beyond Fear</I></A>, Copernicus, 2003</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8792561</guid>
<pubDate>Mon, 15 Dec 2003 12:48:53 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8768021</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : thats cute. I figured there would be creative use of redirectors. <br><br>I mean - you could post one of those "Special offer" links, the ones that nobody expects to look correct because they are long and have affiliate pay-on-click codes in them? - and then  redirect to a phished version of SBC DSL signup page and keep them within it. Then collect credit card numbers for days before the victims noticed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8768021</guid>
<pubDate>Fri, 12 Dec 2003 17:48:59 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8767960</link>
<description><![CDATA[<A HREF="/useremail/u/450886"><b>Googled</b></A> : I was thinking some more about this bug and I came up with an even scarier usage.<br><br>Using the Apache "Redirect" directive you can phish an entire site!  Just put this into your httpd.conf!<br><br><PRE><br>Redirect /test "http://www.domainyouwant.com^A@www.domainyouhave.com"<br></PRE><br><br>Now anyone who visits www.domainyouhave.com/test will be redirected to the phished site!  Doing this makes IE automatically modify EVERY link on the page to a phished version!<br><br><SMALL>--<br>DirecWay DW3000 DRS, SatMex 5 1170 gateway 164, P3-533/256 MB, AOL+ 7.0 4114.10712 on 98SE w/ICS,shared to 2 x 2K Pro, 1 x Redhat Linux 7.3, 1  x Netgear 802.11b</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8767960</guid>
<pubDate>Fri, 12 Dec 2003 17:43:22 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8763624</link>
<description><![CDATA[<A HREF="/useremail/u/491645"><b>Fireshield</b></A> : Thanks  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.  You're right, it does work.  Rather scary!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8763624</guid>
<pubDate>Fri, 12 Dec 2003 09:23:39 EDT</pubDate>
</item>

<item>
<title>Avant Browser</title>
<link>http://www.dslreports.com/forum/remark,8757001</link>
<description><![CDATA[<A HREF="/useremail/u/558165"><b>petrus</b></A> : I experienced the same thing using Avant Browser. Does Avant Browser somehow make IE more secure?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8757001</guid>
<pubDate>Thu, 11 Dec 2003 16:09:15 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8756542</link>
<description><![CDATA[<A HREF="/useremail/u/688507"><b>Urg Comcast</b></A> : The address bar doesn't even say www.paypal.com<br>It says "https://www.paypal.com%01@secure.divo.net/notpaypal/"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8756542</guid>
<pubDate>Thu, 11 Dec 2003 15:28:41 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8756421</link>
<description><![CDATA[<A HREF="/useremail/u/164582"><b>kwitko</b></A> : Interesting, using IE through Avant Browser, I get<br>&raquo;<small>https</small>://<A HREF="https://www.paypal.com@secure.divo.net/notpaypal/">www.paypal.com@secure.divo.net/notpaypal/</A><br><br>But using IE standalone I get:<br>&raquo;<small>https</small>://<A HREF="https://www.paypal.com/">www.paypal.com/</A><br><br>Using Firebird I get<br>&raquo;<small>https</small>://<A HREF="https://www.paypal.com%01@secure.divo.net/notpaypal/">www.paypal.com%01@secure.divo.net/notpaypal/</A><br><SMALL>--<br>"Comparing information and knowledge is like asking whether the fatness of a pig is more or less green than the designated hitter rule."-- David Guaspari</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8756421</guid>
<pubDate>Thu, 11 Dec 2003 15:15:36 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8754332</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : hover your link over his paypal link .. see (phish removed) ?<br><br>I added phish protection to these forums<br><br>but it did work just fine, he is right.<br><br>edit: protection will be lifted shortly <I>just for his post</I>. Try it later if you're still interested.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8754332</guid>
<pubDate>Thu, 11 Dec 2003 11:32:52 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8754169</link>
<description><![CDATA[<A HREF="/useremail/u/491645"><b>Fireshield</b></A> : Hmmmm...when I click it I get &raquo;<small>https</small>://<A HREF="https://secure.divo.net/notpaypal/">secure.divo.net/notpaypal/</A> in the address bar.<br><br>IE Version 6.0.2800.1106.xpsp2.030422-1633]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8754169</guid>
<pubDate>Thu, 11 Dec 2003 11:12:56 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8751791</link>
<description><![CDATA[<A HREF="/useremail/u/826251"><b>espionage007</b></A> : omg no way!! you're one evil genius]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8751791</guid>
<pubDate>Thu, 11 Dec 2003 01:26:05 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8751730</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I figured it would work, as its just a display bug, really. Damn. I updated the news bit to link to your post demonstrating the fake encrypted site that gives no alerts about the certificate not matching what is <I>displayed</I> in the address bar.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8751730</guid>
<pubDate>Thu, 11 Dec 2003 01:11:49 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8751721</link>
<description><![CDATA[<A HREF="/useremail/u/756452"><b>The Way Out</b></A> : Yes, I set it up.  As long as the "real" webhost has a valid SSL certificate (and is issued by a root that is trusted by the browser), no warning is popped up at all.  Scary, huh.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8751721</guid>
<pubDate>Thu, 11 Dec 2003 01:10:03 EDT</pubDate>
</item>

<item>
<title>Re: Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8751713</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : Did you knock this site up? i was going to try an https redirect to see if it could be done, it seemed like it could but I didn't have a domain handy.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8751713</guid>
<pubDate>Thu, 11 Dec 2003 01:07:58 EDT</pubDate>
</item>

<item>
<title>Don&#x27;t trust the Lock icon either!</title>
<link>http://www.dslreports.com/forum/remark,8751690</link>
<description><![CDATA[<A HREF="/useremail/u/756452"><b>The Way Out</b></A> : Want to see something scary?  Try this link:<br><br><A HREF="https://www.paypal.com@secure.divo.net/notpaypal/">https://www.paypal.com</A><br><br>It says PayPal in the URL, but it's not paypal!  You'll notice that it still displays the "Lock" in the bottom right hand corner, too.  Be afraid.  :|]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8751690</guid>
<pubDate>Thu, 11 Dec 2003 01:03:36 EDT</pubDate>
</item>

</channel>
</rss>
