Collected research
Stealing User Information Via Automatic Form Filling
ha.ckers.org web application security lab - Archive » Stealing User Information Via Automatic Form Filling
Browser and toolbar autofill features populate fields by name without asking the user, so an XSS payload can inject a hidden form carrying common field names and harvest whatever autofill supplies: name, address, card number, expiry. No social engineering is needed and the form need never be visible.
Record
- Document
- ha.ckers.org web application security lab - Archive » Stealing User Information Via Automatic Form Filling
- Published by
- ha.ckers.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .