|
|
|
|
|
by lmm
1691 days ago
|
|
> That way the server doesn't know what the "verified" image actually looks like. Right, but it doesn't need to - it just has to construct a page that has the "verified" image on the left and the malicious URL on the right. Which is very difficult to rule out. |
|