{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 38 - Web Security Known Web Attacks | Episode 4: From Phishing to Reverse Clickjacking","slug":"course-38-web-security-known-web-attacks-episode-4-from-phishing-to-reverse-clickjacking","published_at":"2026-07-05T06:00:02+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-38-web-security-known-web-attacks-episode-4-from-phishing-to-reverse-clickjacking","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-38-web-security-known-web-attacks-episode-4-from-phishing-to-reverse-clickjacking--72711733","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72711733/weaponizing_browser_tabs_with_window.mp3","summary":"In this lesson, you’ll learn about: window.opener risks, phishing via tab manipulation, and Same Origin Method Execution (SOME)1. What is window.openerUsing JavaScript:🔹 Definition: A property that gives a newly opened tab access to its parent tab 🔹 When it exists: When a link uses target=\"_blank\" 👉 Key Insight A child tab can control or modify the parent tab2. Why window.opener is Dangerous🔹 Core issue: Trust between tabs is implicit 🔹 Risk: The new tab may be malicious or compromised 👉 Key Insight Opening external links creates a hidden trust boundary3. Phishing via window.opener🔹 Attack flow: User clicks link on trusted site New tab opens (attacker-controlled) Attacker uses window.opener Parent tab is redirected to fake login page 👉 Key Insight User thinks they’re still on the trusted site4. Why This Phishing Works🔹 Psychological factor: User trusts the original tab 🔹 Technical factor: URL changes silently in background 👉 Key Insight This attack combines technical manipulation + human trust5. Same Origin Method Execution (SOME)🔹 Definition: Triggering actions in another window using limited scripting capabilities 🔹 Also known as: Reverse clickjacking 👉 Key Insight Even without full XSS, attackers can still execute actions indirectly6. How SOME Works🔹 Core idea: Child tab keeps reference to parent Waits for parent to reach sensitive state Triggers actions programmatically 👉 Key Insight Timing + reference = powerful attack vector7. Weak Callback Exploitation🔹 Targets: JSONP endpoints Legacy browser integrations 🔹 Why they matter: Accept limited characters Still allow function execution 👉 Key Insight Even restricted inputs can be abused for execution8. Example Impact of SOME🔹 Possible actions: Trigger button clicks Submit forms Perform sensitive operations 👉 Key Insigh…","meta_description":"In this lesson, you’ll learn about: window.opener risks, phishing via tab manipulation, and Same Origin Method Execution (SOME)1. What is window.openerUsi…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1266,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-38-web-security-known-web-attacks-episode-4-from-phishing-to-reverse-clickjacking/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-38-web-security-known-web-attacks-episode-4-from-phishing-to-reverse-clickjacking.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}