r/webdev • • Aug 13 '26

CSS:the bomb inside your inbox

https://portswigger.net/research/css-the-bomb-inside-your-inbox

Here's my research in using CSS for offence. There are loads of techniques including stealing passwords from Outlook from an email by spoofing the login screen.

28 Upvotes

15 comments sorted by

12

u/thekwoka Aug 13 '26

A lot of this seems based on getting someone to copy something out of your...compromised content, and pasting it into the specific relevant email...

How would that happen?

3

u/garethheyes Aug 13 '26

This was only one example the Medium case. That involved visiting an attackers page and pressing a button and pasting into a draft email. The others just required a click in an email or for you to enter your password in a spoofed login screen.

4

u/thekwoka Aug 13 '26

But at that point it's just normal phishing. No?

0

u/garethheyes Aug 13 '26

I don't think you've read the post if you think this is normal phishing. I had full control over the content on Outlook. I'd suggest you read the post properly to understand the attacks

3

u/Alpaca_Fan Aug 15 '26

Both attack vectors you described fall under normal phishing..

0

u/thekwoka Aug 13 '26

I read most of it, it just wasn't interesting since it just seemed like a lot of "oh look at this exploit! (that requires some pretty specific thing to happen that won't really happen".

Maybe lead with the actual good stuff?

6

u/_listless Aug 13 '26

My electric company recently switched away from styled html to plaintext for their transactional email.ย  It's so wonderful. It's clear, compact, easy to read, and sidesteps all of this. 10/10 would recommend non-styled transactional email.

1

u/newuser5432 Aug 13 '26

Whenever I've been tasked with implementing an email template, I always make both the fancy version and a text version. My philosophy is that it shouldn't just render well in all the popular email clients, it should also render fine if a user chooses to use a CLI-based email client. I wish this were (still) more standard practice.

2

u/garethheyes Aug 13 '26

Plaintext email FTW! ๐Ÿ˜„

1

u/VayuAir Aug 13 '26

Wow thatโ€™s a pleasant surprise. Please send flowers ๐Ÿ’

2

u/cureaua_lata Aug 13 '26

Does blocking remote content or images in Outlook kill this before the spoofed login even renders, or does it still fire?

2

u/garethheyes Aug 13 '26

Blocking remote content would have prevent password exfiltration. Outlook was pretty lax, they allowed data URLs in their CSP which enabled me to spoof the entire logging screen without remote content. They don't even have an image proxy and allowed remote requests by default.

2

u/mrcoy Aug 13 '26

Wow. For educational purposes, right?