Web Hack List

Collected research

Using the HTML5 Fullscreen API for Phishing Attacks

Using the HTML5 Fullscreen API for Phishing Attacks » Feross.org

A link whose status bar shows a bank's real URL instead calls preventDefault on click, enters HTML5 fullscreen, and paints screenshot-based OS and browser chrome matched to the visitor's platform, padlock included. Because fullscreen entry is barely signalled and change blindness hides the swap, the fake address bar is convincing. A working demo and browser-vendor responses are included.

Record

Document
Using the HTML5 Fullscreen API for Phishing Attacks » Feross.org
Researcher
Feross Aboukhadijeh
Published by
feross.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Feross Aboukhadijeh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .