Video wird geladen...
Video konnte nicht geladen werden
I stole an Outlook password with nothing but CSS inside an email ๐ Whitepaper below ๐
52,212 Aufrufe โข vor 1 Monat โขvia X (Twitter)
13 Kommentare

This video is from my research "CSS: the bomb inside your inbox". Whitepaper & slides:

Outlook renders untrusted CSS inside the trusted mail UI. The breakout is a gadget in Outlook's own code: an allow-listed data attribute causes it to append position:fixed, which lets the message cover the chrome with a fake login form.

Microsoft: that's a feature.

Amazing. That's like making a helicopter out of scrap metal.

@WebSecAcademy Waiting for css for hackers book edition ๐

@WebSecAcademy I might do that at some point ๐

@WebSecAcademy

โNo JavaScriptโ does not mean โno active content.โ If untrusted email CSS shares a rendering context with trusted webmail controls, sanitizer quirks can become UI manipulation or credential theft. Strong isolation, such as sandboxed rendering, matters more than an ever-growing CSS blocklist.

Wild that you pulled this off with just CSS ๐ Makes you think twice about every email you open. How long did this take you?

A lot of testing. Many months.

next level stuff ๐ฅ๐ฅ๐ฅ๐ฅ๐ฅ๐ฅ๐ฅ๐ฅ๐ฅ

Its over for grandmas around the world

Coooool
