Phishing ngokusebenzisa ujongano lwesikhangeli esifanisiweyo kwifestile evelelayo

Ulwazi luye lwapapashwa malunga nendlela yokukhwabanisa evumela umsebenzisi ukuba enze inkohliso yokusebenza kunye nefom esemthethweni yokuqinisekisa ngokuphinda aphinde adibanise i-browser interface kwindawo eboniswe phezu kwefestile yangoku usebenzisa iframe. Ukuba abahlaseli bangaphambili bazame ukukhohlisa umsebenzisi ngokubhalisa imimandla ngopelo olufanayo okanye ukuxhaphaza iparamitha kwi-URL, ngoku usebenzisa indlela ecetywayo usebenzisa iHTML kunye neCSS, iziqalelo zizotywa phezulu kwefestile ezivelelayo eziphinda-phinda ujongano lomkhangeli zincwadi. iheader enamaqhosha olawulo efestile kunye nebar yedilesi, equka idilesi engeyiyo eyona dilesi yomxholo.

Phishing ngokusebenzisa ujongano lwesikhangeli esifanisiweyo kwifestile evelelayo

Ukuthathela ingqalelo ukuba iisayithi ezininzi zisebenzisa iifomu zokuqinisekisa ngeenkonzo zomntu wesithathu ezixhasa iprothokholi ye-OAuth, kwaye ezi fom ziboniswa kwifestile eyahlukileyo, ukuvelisa ujongano lomkhangeli ongeyonyani kunokulahlekisa nomsebenzisi onamava kunye nenkathalo. Indlela ecetywayo, umzekelo, inokusetyenziswa kwiindawo eziqhekekileyo okanye ezingafanelanga ukuqokelela idatha yephasiwedi yomsebenzisi.

Umphandi othe watsalela ingqalelo kule ngxaki upapashe iseti esenziwe ngokulungelelaniso efanisa ujongano lweChrome kwimixholo emnyama kunye nekhanyayo yeMacOS kunye neWindows. Ifestile ezivelelayo zenziwe kusetyenziswa iframe evezwe ngaphezulu komxholo. Ukongeza inyani, iJavaScript isetyenziselwa ukubophelela abaphathi abakuvumela ukuba uhambise idummy window kwaye ucofe kumaqhosha olawulo efestile.

Phishing ngokusebenzisa ujongano lwesikhangeli esifanisiweyo kwifestile evelelayo


umthombo: opennet.ru

Yongeza izimvo