Yesterday, we learned of an ad-based exploit that stole SSH keys and FTP passwords. Today, Firefox 39.0.3 has a fix. blog.mozilla.org/security/20…
17
380
139
.@mozsec It's time for Firefox to treat ad iframe as if they had the “sandbox” attribute, and ad script tags as XSS attacks.
2
8
11
Meanwhile, the ad industry wants to extend <iframe> so it can cover the page and read everything other than your pw: iab.net/safeframe
8
38
28


