很猥琐的submitjacking,在群里看到的。应该不是owasp里提到的clickjacking,但也挺有意思,OWASP会议上的Clickjacking可以看看刺写的OWASP会议上的Clickjacking。
XML/HTML代码
- <form name="my_form_tres" action=""
- onSubmit=window.open("http://www.example.com")>
- <input type="submit" id="my_submit_button_tres"
- style="position:absolute;left:0px;visibility:hidden;"/>
- <a href="http://www.breakingpointsystems.com"
- onMouseUp=document.getElementById('my_submit_button_tres').click()>Fake
- link (onmouseup and click)</a>
- </form>
