4 ms·
I still don't get it. How are you getting a successful request and a page render for the 3rd party site, but not able to query the 3rd party DOM? If you phish
by Novashi 8y ago
I still don't get it.
How are you getting a successful request and a page render for the 3rd party site, but not able to query the 3rd party DOM?
If you phished someone, there's probably better things you can do to lead to a fuller compromise.
- shawnz 8y agoIt's described right in the article: embed the victim page in an iframe. Because of the same-origin policy you shouldn't be able to access its DOM, but with this trick, you can.