Skip to content

Comment on A clickjacking vulnerability in WhatsApp that enables phishing attacksparent

Comments

That was the initial idea, but it failed because Whatsapp traffic is end to end encrytped. The second idea, which actually worked, was to put a breakpoint in Whatsapp while running in an emulator.

No, not an emulator. Just using your browser's JavaScript debugger.

You can do that on any website.

Yeah, the article also says "WA web’s javascript was uglified and minified, however after a while of searching I found the right place."

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.