Extended Validation certificates and XSS considered harmful

  • A cross-site scripting vulnerability on the popular SourceForge.net website shows how Extended Validation SSL certificates could be exploited by fraudsters. Piggybacking on the anticipated extra trust instilled by the presence of an EV SSL certificate, arbitrary content could be injected onto the secure page at SourceForge to create a very convincing phishing attack.

Related Stories

Hearables: The Next Big Thing in Wearable Technology

Choosing an embedded software development team – the do’s

Agricultural News:Soybeans, Bees, Hurricane Matthew and Chickens