The Art of Same-Site Phishing

We all know how to prevent phishing attacks, just check if the domain you're on is legitimate. But what if we inject the phishing HTML form on the real site! During this talk, we'll explore this idea from a basic concept to some protections that we can bypass, as well as features that are commonly exploitable. This won't be your standard phishing talk, but rather a deep technical dive into how we can design realistic forms with limited HTML injections involving some novel techniques. Including: * Bypassing the form-action Content Security Policy directive to exfiltrate credentials * Finding and chaining CSS class gadgets * Without CSS, using SVG to design a malicious form * Phishing inside a fully sandboxed iframe

    Speaker

    FURTHER SESSIONS

  • 1979 called. They already figured it out.

  • A Few Dollars to Disappear: Breaking C2 Beaconing Detection

  • Ants, Bricks and Spiders: Threat Emulation on the VMware Stack

  • Capture The Flag

  • Join us in Amsterdam!

    November 19, 2026

    Hang out, learn something awesome and make new friends.

    Get Tickets