Collected research
Navigation Hijacking (Frame/Tab Injection Attacks)
Hijacking Innocent Frames
pdp on navigation hijacking: a page opens a window to a trusted site, polls it for login completion using script tags and error-code offsets, then rewrites w.location once the user has authenticated, dropping a lookalike "login failed" page under them. The address bar is never rechecked, so credentials are re-entered to the attacker.
Record
- Document
- Hijacking Innocent Frames
- Researcher
- pdp
- Published by
- gnucitizen.org
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .