Web Hack List

Collected research

Stroke triggered XSS and StrokeJacking

On rubyheroes.com a keyup handler passed the input box's contents to jQuery html(), so the XSS could only be injected by the victim typing it character by character. The author pairs this with Zalewski's StrokeJacking: a hidden iframe takes focus for the characters the attacker wants, so the victim types the payload into the target site while believing he is typing something harmless.

Record

Researcher
lava
Published by
blog.andlabs.org
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .