[WEB SECURITY] Exploiting Stroke triggered XSS with StrokeJacking
lavakumar.in at gmail.com
Wed Apr 7 16:22:33 EDT 2010
I have mentioned about 'urlbarsnakesonaplanejacking' in my post as well.
There are two major differences here:
1) The victim is on the attackers website and not on the vulnerable site
2) He is keying in something that does not even look remotely identifiable
Hope this helps.
On Thu, Apr 8, 2010 at 1:32 AM, gaz Heyes <gazheyes at gmail.com> wrote:
> On 7 April 2010 11:33, Lavakumar Kuppan <lava at andlabs.org> wrote:
>> I have written a post on how StrokeJacking can be used to exploit a type
>> of XSS where the payload can only be injected through the keystrokes of the
>> victim - 'Stroke triggered Cross-site Scripting'.
> I have found a similar flaw in Google, if you visit google.com and type
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the websecurity