| Always hand type in the urls of any sites you want to deal with WRT money. This exploit really only works for email phishing scams (i.e. where they email you with a link to "$bank webpage" asking for passwords, account numbers, etc) and still needs you to click a link within the email.
Moral of the story (as it's been with phishing things for a while): just type in your bank's website by hand if you need to go there, don't click links from emails. The Mozilla crew will probably have a patch for this by the end of the day (there's a couple fixes for now, one listed in your link above, one listed on another site linked in one of the replies that deals with editing compreg.dat).
Substitute 'paypal' for 'bank' as necesary. |