Using the HTML5 Fullscreen API for Phishing Attacks
81–90 of 133 posts
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#82Both Chrome and Firefox show warnings when a page uses the fullsrceen API. Is there a browser out there that doesn't?
The latest version of Safari shows no warning on fullscreen, making users very vulnerable. The only indication is a short, half-second animation (it's much shorter than the usual OS X fullscreen animation). After that, there's no indication that you're in fullscreen mode.
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#83Re: Using the HTML5 Fullscreen API for Phishing Attacks
#84Re: Using the HTML5 Fullscreen API for Phishing Attacks
#85Re: Using the HTML5 Fullscreen API for Phishing Attacks
#86Thank you, Xmonad, for not supporting chrome fullscreen in your default configuration.
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#87Re: Using the HTML5 Fullscreen API for Phishing Attacks
#88(Certainly, most any adequate web developer with nefarious intensions would be able to reproduce this quite easily. But why make it point-and-click easy for them?)
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#89The user can hover their mouse over the link and their status bar will show https://www.bankofamerica.com, as expected. Google search results use a similar technique to show you the "right" link when you hover. (It's only when you click the link does it muck around with the DOM to insert the google.com/... redirect link.)
This is pissing me off. The link hover should be sacred, browsers shouldn't allow any trickery there.
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#90On linux it tries to emulate Ubuntu with default settings, while I have Cinnamon and different theme and fonts, different user name. Didn't terrify me.