YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

HTML5 Exploit Uses FullScreen API for Phishing Attempts

Posted On 17 Oct 2012
By : admin

YNOT – A computer science student has developed a proof-of-concept attack that exploits the FullScreen application programming interface in HTML5 to carry out phishing schemes in ways that have security experts on edge. Unlike many other attacks, the exploit relies on social engineering rather than faulty code.

Stanford University student Feross Aboukhadijeh, 21, proved the FullScreen API allows hackers to insert subtle, if malicious, code that can hijack an end-user’s browser, replacing it with a sort of overlay designed to steal private information or distribute malware.

In his demo, Aboukhadijeh used what appeared to be a legitimate link to the Bank of America website. Users who hovered over the link saw what appeared to be the correct URL destination in the bottom left corner of the screen, as they normally would. In reality, though, clicking the HTML link automatically launched FullScreen browsing, obscuring the actual URL to which the user was redirected. A redirection capable of obscuring actual URLs represents a serious phishing threat.

The fake FullScreen browser doesn’t match bookmarks, browser customizations, menu bars, or plugins — at least yet — so users paying attention might notice the sneaky switch. Less savvy users might easily be hoodwinked into providing all kinds of sensitive information, especially if they believe they are interacting with a trusted site.

Developers of the major web browsers reportedly are scrambling for a solution that will warn users they have entered FullScreen mode and may be redirected to a site not of their choosing. Microsoft’s Internet Explorer 10 does not support the FullScreen API, so for once IE users are relatively safe — at least in the short term. Google Chrome version 22 and later offers some notice that a user has entered FullScreen mode, although the notice is easily overlooked. Apple’s Safari version 6.01 and later provides no notice. Only version 10 and later of Mozilla’s Firefox provides conspicuous notice.

  • google-share
Previous Story

New Frontier – LFP Deal Generates Market Action, Lawsuit Threat

Next Story

One-Night Stands Not Out of the Ordinary

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • Gaelic WWW Conference
    News & Resources
  • Web Wise Cards
    Alternative Online Billing
  • Performer Availability Screening Services
    Health and Medical Services
  • Premiere Listing

    The European Summit

    More Details

RECENT

POPULAR

COMMENTS

Ria Bentley Unveils Hot New Scene with Masculine Jason

Posted On 16 Jun 2025

Coco Bae Takes Her 1st Ride in the Fake Taxi

Posted On 16 Jun 2025
Corey D. Silverstein to Host Webinar on SCOTUS Age Verification Ruling

Corey D. Silverstein to Host Webinar on SCOTUS Age Verification Ruling

Posted On 16 Jun 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Sex Toy Collective Dildo Sculptor

Posted On 19 Mar 2019

Find a good sex toy is now a problem,...

Posted On 18 Mar 2024

Thanks to the variety of sex toys, I can...

Posted On 02 Feb 2024

I understand the concerns about...

Posted On 05 Jan 2024

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy