Web Hack List

Collected research

Stealing User Information Via Automatic Form Filling

ha.ckers.org web application security lab - Archive » Stealing User Information Via Automatic Form Filling

Browser and toolbar autofill features populate fields by name without asking the user, so an XSS payload can inject a hidden form carrying common field names and harvest whatever autofill supplies: name, address, card number, expiry. No social engineering is needed and the form need never be visible.

Record

Document
ha.ckers.org web application security lab - Archive » Stealing User Information Via Automatic Form Filling
Published by
ha.ckers.org
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .