6 ms·
I do like the approach and when it works great thats fantastic - please be careful of this as an attack vector. I know of at least one bank where this was expl
by aplummer 4y ago
I do like the approach and when it works great thats fantastic - please be careful of this as an attack vector.
I know of at least one bank where this was exploited, because people see the base url, assume safe, and can't read the embedded escape / javascript in the longer part. Especially when the link is zipped into a little clickable thing and you can't see the URL at all.