Microsoft Developer Network > 포럼 홈 > Live Framework > LiveID Protection from Spoofers; A must-have feature request
질문하기질문하기
 

답변됨LiveID Protection from Spoofers; A must-have feature request

  • 2009년 2월 2일 월요일 오전 12:53Chris Lamont Mankowski - Test 사용자 메달사용자 메달사용자 메달사용자 메달사용자 메달
     
    Since it's relatively easy for anyone to create a [Sign in] link on their web page and redirect you to a bogus authentication page has anyone in the LiveID team put any thought into how to protect against this?

    For example, a user goes to a company site and mistypes the url... say company.co.uk instead of company.com.  Well company.co.uk is a spoofing site that looks like company.com except that the sign-in page sends you to some ASPX page that visually looks like a Federated or LiveID page, but it's saving whatever the user types in there (user/pass) to a local txt file. 

    What is to prevent the ASPX page from transparently redirecting the user to the real site using a .js form post?

    Can we get some kind of standard published from secure@microsoft.com that says "Hey enduser, look at the URL up top and make sure it says xxx.yyy.zzz, if not call your it security department"  or some other validation... 

    One possible solution is to have the authenticating server respond with the cryptographically signed IP address of the requesting user and use this for validation.

    -Chris

답변

모든 응답