1

If the website is legitimate and the attacker exploited that legitimate website, and the attacker gains access to a victim's system that visits the website, then it is a drive-by compromise.

However, if the attacker built the website, and the attacker gains access to a victim's system that visits the website, will it be called a drive-by compromise?

Definition of drive-by compromise

schroeder
  • 123,438
  • 55
  • 284
  • 319

1 Answers1

1

Both are types of Drive-By Compromise. It doesn't matter who owns the site. What matters is that the client is compromised by simply processing the malicious code delivered by the site.

schroeder
  • 123,438
  • 55
  • 284
  • 319