Hacker News new | ask | show | jobs
by mukesh610 1795 days ago
HTML5 History API allows for modifying the URL too.

If an attacker leverages an XSS they can exactly replicate the login page, URL and all, only limited by payload size and modern protections like CSP.