Scraping Login Credentials With XSS
ID: 804e4162-6b0d-5d82-924d-a8c39cae4b5f
STIX ID: report--804e4162-6b0d-5d82-924d-a8c39cae4b5f
Feed Name: TrustedSec blog
Threat Score
This blog post demonstrates how an unauthenticated reflected XSS can be weaponized into an IFrame trap that presents a real or fake login page, scrapes user-entered credentials via injected JavaScript polling, and exfiltrates them to an attacker-controlled server; it includes implementation details, screenshots, and a linked gist, and cites OWASP mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
