<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CSS on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/css/</link><description>Recent content in CSS on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 08 Aug 2026 14:35:36 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/css/index.xml" rel="self" type="application/rss+xml"/><item><title>Outlook CSS Attack Fakes a Microsoft Sign In to Steal Your Password</title><link>https://hackingpassion.com/css-webmail-keylogger-outlook/</link><pubDate>Sat, 08 Aug 2026 14:35:36 +0200</pubDate><guid>https://hackingpassion.com/css-webmail-keylogger-outlook/</guid><description>&lt;p>CSS in an email put a fake Microsoft sign-in over a live Outlook inbox and read the password letter by letter. Opening the message is enough. Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail gave way. 🧐&lt;/p>
&lt;p>&lt;strong>Microsoft and Google still have not fixed their part.&lt;/strong>&lt;/p>
&lt;p>Webmail has a problem it has never fully solved. Someone sends you HTML, and that HTML has to be displayed inside a page that also holds your inbox, your buttons and your account. To handle that, webmail runs the message through a sanitizer, which strips or rewrites anything it considers dangerous and hands what is left to the browser. The weak spot sits in that word, &lt;em>considers&lt;/em>. A sanitizer has its own reading of the HTML and CSS, the browser has another, and where those two readings differ you get a gap. Some clients go a step further and let the browser parse the message first, then filter what the browser produced. That output can be pushed back into something malicious too.&lt;/p></description></item></channel></rss>