Ask HN: Safari omnibar spoofing vulnerability?
2 comments
Click this using Mountain Lion Safari and look in your address bar to see what I mean: http://www.google.com/search?q=www.apple.com
It kind of does. But to exploit the vulnerabilty, one must change the search engine first to a "spoofing" one. I don't know if this can be done via extensions as is done in chrome.
However - this means that if you search for an _actual_ url, it _also_ gets displayed in the url bar.
If you have Google as your default search engine, and you click this url: http://www.google.com/search?q=www.apple.com you will see www.apple.com in your address bar.
Isn't this a vector for a spoofing attack? Couldn't someone craft a "search engine" that makes it look like you're on a facebook.com login page, and use it to steal passwords?