Web Hack List

Other nomination

Using the HTML5 Fullscreen API for Phishing Attacks

A link whose status bar shows a bank's real URL instead calls preventDefault on click, enters HTML5 fullscreen, and paints screenshot-based OS and browser chrome matched to the visitor's platform, padlock included. Because fullscreen entry is barely signalled and change blindness hides the swap, the fake address bar is convincing. A working demo and browser-vendor responses are included.

Record

Researcher
Feross Aboukhadijeh
Published by
feross.org

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Feross Aboukhadijeh, first published at the original source. Preserved copies are kept so the citation survives its host.