|
|
|
|
|
by nemothekid
3692 days ago
|
|
>What does replacing the auth page gain the attacker? If the spoof app has a "Connect with Twitter* (and you don't have the Twitter app installed), and then a webview is opened, the spoof app can replace Twitter's login page with their own, and capture the username and password. |
|
While a malicious application can inject JavaScript to intercept the username, this alone is useless to an attacker.