seamless bait-and-switch

看板Bugtraq作者時間14年前 (2011/12/09 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/5 (看更多)
Hello world, Another whimsical browser proof-of-concept: http://lcamtuf.coredump.cx/switch/ It seems that relatively few people realize that holding a JavaScript handle to another window (either because we opened it, or because the window was at some point displaying our content) allows the attacker to tamper with the location and history objects at will, largely bypassing the usual SOP controls. With some minimal effort and the help of data: / javascript: URLs or precached pages, this can be leveraged to replace content in a manner that will likely escape even fairly attentive users. /mz PS. Obligatory plug: http://lcamtuf.coredump.cx/tangled/
文章代碼(AID): #1EuFjWe7 (Bugtraq)
文章代碼(AID): #1EuFjWe7 (Bugtraq)