Bill
No favorite files added yet
(Oct 31, 2006 - 1:02 AM)
If the event that code is executed prior to the code for the popup window's own page, it can effectively pre-empt the popup window's content, substituting its own.
If a popup blocker is enabled, the exploit should theoretically be disabled. However, if popup blocking is turned off, or if a malicious page is open in one browser window while an "exception site" -- a page where popups are allowed -- resides in another, the exploit is still feasible.
(Jun 17, 2005 - 12:04 PM)
Poor documentation? Netscape edited an entry in the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\Extension.
Microsoft probably didn't document it because it wasn't meant for anyone to change, especially a program from another company.