Skip to content

Latest commit

 

History

History
11 lines (6 loc) · 996 Bytes

README.md

File metadata and controls

11 lines (6 loc) · 996 Bytes

This is a modification of a proof-of-concept of a chrome address spoofing flaw published by David Leo (david.leo () deusen co uk) on the Full Disclosure mailing list.

(According to the original publication, this was reported to Google but it was regarded as a non-vulnerability.)

This version spoofs the HTTPS version of facebook.com. Surprisingly, it even shows the certificate in green:

You can try a live demo but note that you may have to try it a few times for it to work. There's a connection timing condition involved. However if you clone the repo locally, it should work 100% of the time.

Note that you can't interact with the spoofed web page, making the severity of this vulnerability limited as it can't be used to do direct phishing.