Skip to content

Malicious subdomain concern #20

Open
@hober

Description

@hober

This was raised on public-webappsec:

I am also concerning that draft is not considering 3rd level domains take over and how an attacker could advertise a password change URL to get a Beef kind of hooking of clients in a bot fashion.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions