Escalating the Client-Side Attack
There are numerous ways in which a web site may directly attack users who
visit it. Any of these attacks may be delivered via a cross-site scripting flaw in
a vulnerable application (although they may also be delivered directly by any
malicious web site that a user happens to visit).
Log Keystrokes
JavaScript can be used to monitor all keys pressed by the user while the
browser window is active, including passwords, private messages, and other
personal information. The following proof-of-concept script will capture all
keystrokes in Internet Explorer and display them in the status bar of the
browser:
Do'stlaringiz bilan baham: |