Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Stealing passwords from infosec Mastodon - without bypassing CSP

Summary

How an HTML injection in Infosec Mastodon's post filter enabled credential theft without bypassing CSP, abusing quirks in the platform's HTML handling such as title attributes and emoji substitution.
Published
Collected

original ↗

Related coverage

back