Podlipodcast player Webplayer

CyberCode Academy

CyberCode Academy

Course 38 - Web Security Known Web Attacks | Episode 4: From Phishing to Reverse Clickjacking

CyberCode Academy · Jul 5, 2026 · 21:06

0:0021:06

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

In this lesson, you’ll learn about: window.opener risks, phishing via tab manipulation, and Same Origin Method Execution (SOME)1. What is window.openerUsing JavaScript:🔹 Definition:🔹 When it exists:👉 Key Insight
A child tab can control or modify the parent tab2. Why window.opener is Dangerous🔹 Core issue:🔹 Risk:👉 Key Insight
Opening external links creates a hidden trust boundary3. Phishing via window.opener🔹 Attack flow:
  1. User clicks link on trusted site
  2. New tab opens (attacker-controlled)
  3. Attacker uses window.opener
  4. Parent tab is redirected to fake login page
👉 Key Insight
User thinks they’re still on the trusted site4. Why This Phishing Works🔹 Psychological factor:🔹 Technical factor:👉 Key Insight
This attack combines technical manipulation + human trust5. Same Origin Method Execution (SOME)🔹 Definition:🔹 Also known as:👉 Key Insight
Even without full XSS, attackers can still execute actions indirectly6. How SOME Works🔹 Core idea:👉 Key Insight
Timing + reference = powerful attack vector7. Weak Callback Exploitation🔹 Targets:🔹 Why they matter:👉 Key Insight
Even restricted inputs can be abused for execution8. Example Impact of SOME🔹 Possible actions:👉 Key Insight
User doesn’t need to interact—actions happen silently9. Relation to Other Attacks🔹 Similar to:🔹 Difference:👉 Key Insight
SOME is a bypass technique when XSS/CSRF are blocked10. Preventing window.opener Attacks🔹 Best practices:👉 Key Insight
You must explicitly break the opener relationship11. Defense Against SOME🔹 Strategies:👉 Key Insight
Never rely on client-side trust12. Big Security Lesson🔹 Core idea:🔹 Reality:👉 Key Insight
Security requires understanding how features interact, not just codeKey TakeawaysBig PictureYou are learning:👉 How browser tab relationships create vulnerabilities
👉 How attackers exploit trust and timing
👉 How modern defenses evolved from these weaknessesMental ModelUser click → new tab → opener reference → parent manipulation → exploitation

You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy

Episodes: CyberCode Academy

PodliGet the free Podli app
↓ App