As CROSS Site Authentication (short: XSA) one designates a computer safety gap with an aggressor the stranger of passwords to spy can.
This gap can be used, if a Web forum, a Web log or similar systems by not trustworthy users permit a merging of pictures. An aggressor merges in addition any picture into a contribution, which is protected by the Web server. If a user calls the contribution, its Webbrowser requests it to enter user/password combination who can be stored then by the Web server of the aggressor.
CROSS Site Authentication can be favoured by the Browser, by this in the password dialogue clearly enough does not indicate the name of the Web server requesting to the password input.
Complete deactivating of pictures from external source offers a safe protection on the side of the offerer. By clearer dialogues or warning references the Browser could likewise contain the problem.
The safest protection is however in principle attention and distrust in relation to unexpected password dialogues.
Browser, which prevent the Authentikations mechanisms for elements of strange Web servers, embedded into a web page, in principle, offer likewise safe protection. An example for this is Firefox in version 1.5
We found here 31 articles.
We found here 3 related websites.
Index | Privacy | Terms Of Use | Sitemap | Feedback