Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Can you get pwned with CSS? (scotthelme.co.uk)
9 points by todsacerdoti on Feb 23, 2022 | hide | past | favorite | 2 comments


The earliest I've seen this sort of idea (that CSS could be a source of security issues) was in: https://lcamtuf.blogspot.com/2011/12/notes-about-post-xss-wo... (Reflections on a post XSS world from 2011).

Zalewski acknowledges earlier sources.

EDIT: turns out CSS history sniffing is older than this


If an attacker can inject and style elements, they can cover up a login input or menu button with their own elements.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: