Login Register






CSS keylogger filter_list
Author
Message
CSS keylogger #1
Hello all,

For some may already know but, I just stumbled across LiveOverFlow video of this method being used in action. I'm shocked due to being what CSS is/was.
For a method to take place like this, what is the point of disabling JS. Even if you disable it and think you're safe, your personal information is still in a risk situation.
@mothered Would like to hear your thoughts about this.

Reply

RE: CSS keylogger #2
Saw this a while back. Pretty clever, it's one of those things that seems obvious once you learn of it.

Quote: For a method to take place like this, what is the point of disabling JS. Even if you disable it and think you're safe, your personal information is still in a risk situation.
JS is totally different. This CSS method is only dangerous when used as XSS or if used in Stylish/Stylus. With JS, real exploits can be used, like in the case of Spectre (which was patched by making JS' timing functions less accurate). With this, there isn't as much risk.


(11-02-2018, 02:51 AM)Skullmeat Wrote: Ok, there no real practical reason for doing this, but that's never stopped me.

Reply

RE: CSS keylogger #3
(07-22-2018, 03:17 AM)Ender Wrote: Saw this a while back.  Pretty clever, it's one of those things that seems obvious once you learn of it.

Quote: For a method to take place like this, what is the point of disabling JS. Even if you disable it and think you're safe, your personal information is still in a risk situation.
JS is totally different.  This CSS method is only dangerous when used as XSS or if used in Stylish/Stylus.  With JS, real exploits can be used, like in the case of Spectre (which was patched by making JS' timing functions less accurate).  With this, there isn't as much risk.

Oh for sure on your statement. It's honestly shocking to hear since, Most people wouldn't know about this due to what CSS is.

[+] 1 user Likes Vultra's post
Reply

RE: CSS keylogger #4
(07-22-2018, 03:27 AM)Mimiakira Wrote:
(07-22-2018, 03:17 AM)Ender Wrote: Saw this a while back.  Pretty clever, it's one of those things that seems obvious once you learn of it.

Quote: For a method to take place like this, what is the point of disabling JS. Even if you disable it and think you're safe, your personal information is still in a risk situation.
JS is totally different.  This CSS method is only dangerous when used as XSS or if used in Stylish/Stylus.  With JS, real exploits can be used, like in the case of Spectre (which was patched by making JS' timing functions less accurate).  With this, there isn't as much risk.

Oh for sure on your statement. It's honestly shocking to hear since, Most people wouldn't know about this due to what CSS is.

(un)Surprisingly enough, CSS with HTML is Turing complete: https://github.com/elitheeli/stupid-mach...er/rule110


(11-02-2018, 02:51 AM)Skullmeat Wrote: Ok, there no real practical reason for doing this, but that's never stopped me.

Reply

RE: CSS keylogger #5
(07-22-2018, 03:17 AM)Ender Wrote: JS is totally different.  

This ^^

Different and effective In It's own way. It can obtain your location, connection type (Inclusive of ISP, Internal & External IPs), login account type, hardware specs, OS, browser type & version, timezone and the list goes on- all without permission nor any Input from the end user. Collectively, an Identity can be built from the ground up.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: CSS keylogger #6
(07-22-2018, 03:43 AM)mothered Wrote:
(07-22-2018, 03:17 AM)Ender Wrote: JS is totally different.  

This ^^

Different and effective In It's own way. It can obtain your location, connection type (Inclusive of ISP, Internal & External IPs), login account type, hardware specs, OS, browser type & version, timezone and the list goes on- all without permission nor any Input from the end user. Collectively, an Identity can be built from the ground up.

I partially forgot about that. My head was on the other side.

From that being said, that clears that up on the behalf of my post with JS being "pointless".

Reply

RE: CSS keylogger #7
(07-22-2018, 03:50 AM)Mimiakira Wrote:
(07-22-2018, 03:43 AM)mothered Wrote:
(07-22-2018, 03:17 AM)Ender Wrote: JS is totally different.  

This ^^

Different and effective In It's own way. It can obtain your location, connection type (Inclusive of ISP, Internal & External IPs), login account type, hardware specs, OS, browser type & version, timezone and the list goes on- all without permission nor any Input from the end user. Collectively, an Identity can be built from the ground up.

I partially forgot about that. My head was on the other side.

From that being said, that clears that up on the behalf of my post with JS being "pointless".

No problem whatsoever.

JavaScript can be very dangerous when used for malicious Intent. All the above can be achieved by simply "viewing" a webpage, without generating a single click of the mouse.
[Image: AD83g1A.png]

Reply