Collected research
Who Are You? A Statistical Approach to Protecting LinkedIn Logins(CSS UI Redressing Issue)
LinkedIn Security Practices – Find out how we protect you
LinkedIn publishing platform stripped dangerous tags but allowed the class attribute through, so an author could point a link at a site-hosted CSS class that stretches an element across the whole page. The invisible full-page link turns any click on the article into navigation to an attacker-chosen phishing or malware site.
Record
- Document
- LinkedIn Security Practices – Find out how we protect you
- Researcher
- Jovon Itwaru
- Published by
- Topic
- Other
In the archive
Related sources
- LinkedIn Security Practices – Find out how we protect you
- CVE-2015-2156: HttpOnly bypass in Play Framework Advisory
- Netty cookie parser fix for CVE-2015-2156
Tags
This page is the archive's own catalogue record. The research is the work of Jovon Itwaru, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .