Quantcast
Channel: Files from Michal Zalewski ≈ Packet Storm
Viewing all articles
Browse latest Browse all 25

JavaScript Switcharoo Proof Of Concept

$
0
0
It seems that relatively few people realize that holding a JavaScript handle to another window allows the attacker to tamper with the location and history objects at will, largely bypassing the usual SOP controls. With some minimal effort and the help of data: / javascript: URLs or precached pages, this can be leveraged to replace content in a manner that will likely escape even fairly attentive users.

Viewing all articles
Browse latest Browse all 25

Trending Articles