Hacking the <a> tag in 100 characters

Results 1 to 9 of 9
  1. #1
    ...[ White Rabbit ]... MentaL is offline
      Administrator  Rank
    Jan 2001 Join Date
    31,753Posts

    Showoff Hacking the <a> tag in 100 characters

    Hacking the <a> tag in 100 characters

    I found this quite interesting. Given how simple it is to spoof a link you would figure this is a considerable oversight.


  2. #2
    DBO Freak xDarKyx is offline
    MemberRank
    Mar 2011 Join Date
    280Posts

    Re: Hacking the <a> tag in 100 characters

    Firefox seems to have it fixed either.
    I've tried it.

  3. #3
    Browncoat Robert is offline
    Old SchoolRank
    Mar 2003 Join Date
    UKLocation
    8,658Posts

    Re: Hacking the <a> tag in 100 characters

    Links to paypal fine for me?

    Could be that I've always used NoScript for years now.

  4. #4
    Omega Ron is offline
    MemberRank
    Apr 2005 Join Date
    Location
    8,990Posts

    Re: Hacking the <a> tag in 100 characters

    Or, you know, just look at the address bar before you type in anything. lol

  5. #5
    Veni, Vidi, Vici Arcelor is offline
    MemberRank
    Jan 2010 Join Date
    Delhi, IndiaLocation
    1,763Posts

    Re: Hacking the <a> tag in 100 characters

    Quote Originally Posted by Robert View Post
    Links to paypal fine for me?

    Could be that I've always used NoScript for years now.
    The bug was reported to firefox, opera, chrome. Got fixed.

  6. #6
    The Gamma..? EliteGM is offline
    MemberRank
    Jul 2006 Join Date
    NandolandLocation
    4,077Posts

    Re: Hacking the <a> tag in 100 characters

    NoScript probably prevents it too though.

  7. #7
    Ginger by design. jMerliN is offline
    MemberRank
    Feb 2007 Join Date
    2,497Posts

    Re: Hacking the <a> tag in 100 characters

    This article is retarded. Why would you change the href on a tag? All you have to do is preventDefault on the event and just set the window location.

    Code:
    function loljacked(event){
        event.preventDefault();
        window.location = 'http://www.google.com';
    }
    Array.prototype.slice.call(document.querySelectorAll('a')).forEach(function(link){
      link.addEventListener('click', loljacked);
    });
    Open your console and run it.

  8. #8

    Re: Hacking the <a> tag in 100 characters

    Quote Originally Posted by Arcelor View Post
    The bug was reported to firefox, opera, chrome. Got fixed.
    No, it works in Google Chrome unless you open it in a new tab.

  9. #9
    Member myoxe is offline
    MemberRank
    Jan 2013 Join Date
    52Posts

    Re: Hacking the <a> tag in 100 characters

    Quote Originally Posted by Jubatus View Post
    No, it works in Google Chrome unless you open it in a new tab.
    It works on firefox too.



Advertisement