• Get hidden content from password fields Sce­nario: Use JavaScript for extrac­tion. Copy and pase the fol­low­ing into the web browser’s console: Extract keystrokes live from a Browser Sce­nario: Do: Extract Cookies Sce­nario: Inject/Do: Extract local / session storage Like above: Stealing site passwords Sce­nario: Then, inject JS which adds an invis­i­ble user/username/name text field and…

  • Short: A user opens a link (e.g. from a phish­ing email) which has a injec­tion in the URL which is then exe­cut­ed on the site as long as the user is logged in. See also com­mand injec­tions post. Class­es: Tip: