Collected research
Stroke triggered XSS and StrokeJacking
On rubyheroes.com a keyup handler passed the input box's contents to jQuery html(), so the XSS could only be injected by the victim typing it character by character. The author pairs this with Zalewski's StrokeJacking: a hidden iframe takes focus for the characters the attacker wants, so the victim types the payload into the target site while believing he is typing something harmless.
Record
- Researcher
- lava
- Published by
- blog.andlabs.org
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .