As explained at BoingBoing:
Shmoo Group exploit: 0wn any domain, no defense existsPablos sez, "
Shmoocon ended
today. And just to prove The Shmoo Group wasn't sitting on their asses
for the entire time while planning the con - A new exploit was demo'd
by EricJ that left all jaws our on the floor. Want to own ANY domain?
Want a trusted SSL cert for it? Check it out
here.We 0wnz0rd PayPal, but left the rest for you. We have no idea how to
fix this and neither do the browser developers. Official advisory
here. Phishing attacks of doom coming soon."
Link
(Thanks, Pablos!)
No permanent fix has been devised as yet, but the latest on how to disable the loophole is at
Tech.Life.Bloggedlinks: digg this del.icio.us technorati reddit