Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I personally find the RLO / LRO issue much more concerning. I just tested Chrome and Firefox and found it works in URLs. You could rewrite pyapla.com to paypal.com and phish people easily.


I've done a bit more testing and found that while it can be used in URLs it's problematic. When pasted in the navigation bar it causes errors in both Chrome and Firefox. There's probably a way to exploit this and make it work but I don't have time to dig into it right now.


Absolutely! I wouldn't call myself as "unwary", but I would totally click a file with .jpg extension! (the article says 'Unwary people treat this file as a picture'). EXE is especially dangerous because you can make "SEXe.jpg". Who wouldn't click that?

But I guess from now on I look at the chars to the left of the dot as well..




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: