Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But then the attacker URL will be different.

That doesn't look like a new attack vector, this is called phishing, isn't it?

XSS means you can inject and persist code in a webpage maintaining the same URL accessed by other users.

If you create a bigbank-fake.com and copy a manipulated version of bigbank.com's HTML, this is not XSS.



Correct, except that in this case ALL the sites use "bigbank.com"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: