3 ms·
Wouldn't it be just as simple for an attacker to persuade a victim to paste a string starting with "javascript:" into the URL bar?
by phaer 13y ago
Wouldn't it be just as simple for an attacker to persuade a victim to paste a string starting with "javascript:" into the URL bar?
- Cyykratahk 13y agoBoth FireFox and Chrome have been preventing that since around 2011; the pasted url is stripped of the "javascript:" part. But now the malicious instructions tell users to press "j" before pasting the url (which is missing the "j" at the start), which prevents the browsers from detecting and stripping the protocol, thus allowing the script execution.