Tabnabbing, target=_blank, and Related XSS Edges
Lab HTML: target=_blank without rel, opener check in the opened tab, rel=noopener fix, harmless location rewrite — no phishing kit.
Lab HTML: target=_blank without rel, opener check in the opened tab, rel=noopener fix, harmless location rewrite — no phishing kit.
Lab UA / UA-CH request headers, navigator.userAgentData mock dump, nginx log_format for defenders — no exploit targeting.
Lab HTML+JS page: location.hash into innerHTML, name=form clobber of a config object, harmless redacted payload, CSP as the fix.