« October 2006 | Main | December 2006 »

November 2006

November 25, 2006

How to Steal Passwords from Safari's AutoFill

Safari Compass We've all seen the latest [Firefox exploit](http://www.info-svc.com/news/11-21-2006/) that allows a criminal to steal your user id and password without your knowledge. There is even a handy [proof-of-concept](http://www.info-svc.com/news/11-21-2006/rcsr1/) to show you how easy it is to have your password taken. If you use Safari and its AutoFill feature, you will find that Safari does not fill the hidden login form. This is because Safari is smarter and doesn't automatically fill forms that are hidden. You might be tempted to feel safe when using Safari, but you would be making a grave error.

Try this Safari AutoFill scam and see for yourself.

Continue reading "How to Steal Passwords from Safari's AutoFill" »