4 ms·
Explain?
by quonn 2y ago
Explain?
- ramses0 2y agoProbably something like dom-swapping the google login page or whatever. If you can keep arbitrary CSS transitions running, I could imagine doing a bunch of weird stuff where you don't know exactly what box you're typing in to. https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Clickjacking https://developer.mozilla.org/en-US/docs/Web/Security/Attack...
- deleted 2y ago[deleted]
- AshleysBrain 2y agoIs the ability to move elements preserving DOM state really the key to such attacks? Previously you could do the same but the iframe would reload - but if it's a small simple page, it could load very quickly, in which case it doesn't seem all that different to moving the iframe with its existing content.
- weird-eye-issue 2y agoIf you can run arbitrary JS on the Google login page then you could simply intercept the form submission and steal the credentials... Am I missing something?
- jy14898 2y ago> I could imagine doing a bunch of weird stuff where you don't know exactly what box you're typing in to. What stops malicious JavaScript that would have used moveBefore() to just add key event listeners?