4 ms·
Not 100% sure, but if the malicious ad is put on an HTTPS page, it would not be possible to load additional scripts and data from an un-encrypted (HTTP) locatio
by lini 11y ago
Not 100% sure, but if the malicious ad is put on an HTTPS page, it would not be possible to load additional scripts and data from an un-encrypted (HTTP) location as opposed to another valid HTTPS location. Having your malware on an HTTPS site goes around the browser's mixed content restrictions.
- corobo 11y agoYou could just as easily register a separate domain and use HTTPS on that if your goal is to inject scripts in the background. The "problem" being reported here is that the user may think the site is not going to send them malware because it has a green padlock in the address bar