Hacker News new | ask | show | jobs
by thraway2016 3347 days ago
Crafted-content UAF vulns are still occasionally being found in browsers.

To say nothing of unpatched/non-updated browsers.

1 comments

You don't need a trick URL for those.
The point is that simply clicking a dodgy link can, in some cases, own you. No credential acquisition required.
Yes but what does that have to do with the article?
Are you asking what a dodgy URL has to do with the article?
If they get you to click on a link, it doesn't matter what it looks like in the address bar. So what does a malicious link that could be on any domain have to do with domain spoofing?
If you hover over a link in a browser, the URL of the link will be shown as a tooltip, or in the bottom of your browser window.