[Webkit-unassigned] [Bug 31270] Social Engineering Issue with "javascript:" URLs

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon Nov 9 13:53:37 PST 2009


https://bugs.webkit.org/show_bug.cgi?id=31270





--- Comment #4 from Nathan Hammond <bugs.webkit.org at nathanhammond.com>  2009-11-09 13:53:36 PDT ---
The change I am suggesting:

Immediately after execution of a "javascript:" URL, return the location bar to
its prior state.

This would prevent the phishing site from hiding behind the "javascript:" URL.

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list