3 ms·
> One "trusted" site with some malware can be used to attack people that never actually intentionally visit it The only thing that bothers me about this is tha
by emmab 10y ago
> One "trusted" site with some malware can be used to attack people that never actually intentionally visit it
The only thing that bothers me about this is that someone could deliberately embed an iframe of the bugged website similar to a SWATTING attack. So far that doesn't seem to be happening though?
- dogma1138 10y agoIt does, or did, browsers are better protected against iframe injection and various click jacking attacks but it still can happen. If the FBI has a zero day that doesn't need anything but the content being loaded by the browser to execute code on the target you can easily spread it to anyone you like via content injection, email phishing, old school simply via social media "hey look at this http://goo.gl/P!shing".. http://goo.gl/P!shing"... Also since many zero days affect things like flash or the rendering engine it self and thus could be simply exploited via images or any other embedded object you could even do it easier by simply adding that png or webm with the exploit to every forum, blog post, tweet etc.