[VIM] site redirects: vulnerability or no?

Steven M. Christey coley at linus.mitre.org
Wed Nov 16 04:45:47 EST 2005

I'm on vacation so will be brief and comment on threads that I haven't
even read just so this will be here when I get back :)

Phishing... generally for CVE the litmus test is if a "reasonably
cautious" user could be fooled, but if it's only successful for grandmas
and highly un-knowledgeable people then I'll leave it up to the AV/malware
people.  Status bar and SSL icon hacks fall under "fools reasonably
cautious users" for example.

- Steve

