[TYPO3-dev] jumpurl generally insecure?

Sebastian Michaelsen sebastian.gebhard at gmail.com
Tue Jul 24 22:35:12 CEST 2012


Am 24/07/2012 16:17, schrieb Marc Wöhlken:
> I just wanted to fetch some opinions on this topic as I can't quite see
> a) why this should be a general weakness

I will not post a instruction how to do a phishing attack, but generally 
you can give someone a link to a domain he trusts in, but when the user 
clicks it he will be redirected to a bad site.

If he doesn't double check the URL he might become a phishing victim.



More information about the TYPO3-dev mailing list