Skip to main content

Command Palette

Search for a command to run...

Simple URL spoof in address bar

Updated
1 min read
Simple URL spoof in address bar
Z

Hi, I’m a bug bounty hunter and cybersecurity enthusiast who began my journey in 2023. I enjoy exploring and discovering hidden vulnerabilities in browsers, applications, and various platforms—especially those that are rarely examined by others. My focus is on browser and website security issues. I also share my findings and educational content through my YouTube channel, Lazy Cyber Security. https://8da993bf3fa4.ngrok-free.app

Saya menemukan sebuah bug yang sangat sederhana dan mudah direproduksi. Cukup dengan membuka situs milik attacker, lalu dari situ membuka google.com, kemudian coba klik tombol "Back" (navigasi kembali). Jika setelah klik back, URL di address bar tetap menunjukkan google.com, namun konten yang ditampilkan berasal dari situs attacker, maka ini bisa dikategorikan sebagai kerentanan spoofing yang valid.

Contoh skenario eksploitasi:

  1. Korban mengunjungi situs attacker.

  2. Situs attacker membuka https://www.google.com di tab yang sama (misalnya via location.href).

  3. Korban menekan tombol "Back".

  4. Halaman menampilkan konten dari attacker, tetapi address bar masih menampilkan google.com.

More from this blog

B

BountyProofs | Bug Bounty Writeups & Free Tools

37 posts

Explore real-world bug bounty proofs of concept. Learn how ethical hackers find and exploit security flaws across platforms.