YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

HTML5 Exploit Uses FullScreen API for Phishing Attempts

Posted On 17 Oct 2012
By : admin

YNOT – A computer science student has developed a proof-of-concept attack that exploits the FullScreen application programming interface in HTML5 to carry out phishing schemes in ways that have security experts on edge. Unlike many other attacks, the exploit relies on social engineering rather than faulty code.

Stanford University student Feross Aboukhadijeh, 21, proved the FullScreen API allows hackers to insert subtle, if malicious, code that can hijack an end-user’s browser, replacing it with a sort of overlay designed to steal private information or distribute malware.

In his demo, Aboukhadijeh used what appeared to be a legitimate link to the Bank of America website. Users who hovered over the link saw what appeared to be the correct URL destination in the bottom left corner of the screen, as they normally would. In reality, though, clicking the HTML link automatically launched FullScreen browsing, obscuring the actual URL to which the user was redirected. A redirection capable of obscuring actual URLs represents a serious phishing threat.

The fake FullScreen browser doesn’t match bookmarks, browser customizations, menu bars, or plugins — at least yet — so users paying attention might notice the sneaky switch. Less savvy users might easily be hoodwinked into providing all kinds of sensitive information, especially if they believe they are interacting with a trusted site.

Developers of the major web browsers reportedly are scrambling for a solution that will warn users they have entered FullScreen mode and may be redirected to a site not of their choosing. Microsoft’s Internet Explorer 10 does not support the FullScreen API, so for once IE users are relatively safe — at least in the short term. Google Chrome version 22 and later offers some notice that a user has entered FullScreen mode, although the notice is easily overlooked. Apple’s Safari version 6.01 and later provides no notice. Only version 10 and later of Mozilla’s Firefox provides conspicuous notice.

  • google-share
Previous Story

New Frontier – LFP Deal Generates Market Action, Lawsuit Threat

Next Story

One-Night Stands Not Out of the Ordinary

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • Erotic Trade Only
    News & Resources
  • Deutsche Dating Seiten
    Dating Affiliate Programs
  • Adult Site Broker
    General Business Services
  • Premiere Listing

    TrafficStars

    More Details

RECENT

POPULAR

COMMENTS

Lorenzo guest on the Misfit effect Podcast

Posted On 21 Aug 2025

foxslayer Goes Retro in a Speakeasy

Posted On 21 Aug 2025
Free Speech Coalition

FSC: Missouri Age Verification Rule Will Not Take Effect August 30

Posted On 21 Aug 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Someone puts Gal Gadot in one of your vids? Take it down!

Posted On 13 Dec 2017

Hoping viewers can also enjoy a spooky...

Posted On 24 Oct 2023

now a days these type of games will get...

Posted On 17 Jul 2023

good move from adent. these type of...

Posted On 06 Jul 2023

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy