Hacker News new | past | comments | ask | show | jobs | submit login

Nice spoof, hadn't seen this before. It would have gone really well with the RTL address bar spoof (CVE-2014-1723) I reported in Chrome back in February (since fixed in Chrome 34), it would have made the tab very close to indistinguishable from the real thing.



Do you have a screenshot of this exploit in action before it was patched?


Looks like the issue is marked public now in the chromium bug tracker and it has been fixed for a while now in release, so I assume it is ok to link that. The ruse is not perfect due to bolding and coloring, but good enough to fool most people not expecting it, I think, if you look at the bottom part of the second attached screenshot it gives you a good idea of what it looked like:

https://code.google.com/p/chromium/issues/detail?id=337746




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: