HSBC sites vulnerable to XSS flaws, could aid phishing attacks
30 June 2008 | 05:29
What would the perfect phishing attack from a social engineering perspective? The one that compared to using typosquatted domains impersonating the bank’s web application directory structure is in fact using the bank’s legitimate domain names as redirectors due to XSS flaws within. It’s even more interesting to measure the average time it takes for a [...]