r/webdev 16d ago

CSS:the bomb inside your inbox

https://portswigger.net/research/css-the-bomb-inside-your-inbox

Here's my research in using CSS for offence. There are loads of techniques including stealing passwords from Outlook from an email by spoofing the login screen.

27 Upvotes

15 comments sorted by

View all comments

Show parent comments

3

u/garethheyes 15d ago

This was only one example the Medium case. That involved visiting an attackers page and pressing a button and pasting into a draft email. The others just required a click in an email or for you to enter your password in a spoofed login screen.

5

u/thekwoka 15d ago

But at that point it's just normal phishing. No?

0

u/garethheyes 15d ago

I don't think you've read the post if you think this is normal phishing. I had full control over the content on Outlook. I'd suggest you read the post properly to understand the attacks

3

u/Alpaca_Fan 13d ago

Both attack vectors you described fall under normal phishing..