|
|
|
|
|
by hguant
2816 days ago
|
|
Perfectly valid cert for the evil.com domain - someone below pointed out that I flipped the domain names. In reality the "evil" page would look something like "https://www.login.chase/login?id=DEADBEEF/.evil.com". For a non-trivial number of users, that's enough - "I see the nice green lock, I see chase, and some crazy web address characters that are always there". |
|
Unless you're doing something super clever with characters that I'm not understand, that's not how urls work. ".evil.com" is clearly part of the query parameter.