![]() |
|
CSS keylogger - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: Coding (https://sinister.li/Forum-Coding--71) +--- Thread: CSS keylogger (/Thread-CSS-keylogger) |
CSS keylogger - Vultra - 07-22-2018 Hello all,
For some may already know but, I just stumbled across LiveOverFlow video of this method being used in action. I'm shocked due to being what CSS is/was. For a method to take place like this, what is the point of disabling JS. Even if you disable it and think you're safe, your personal information is still in a risk situation. @mothered Would like to hear your thoughts about this. RE: CSS keylogger - Blink - 07-22-2018 Saw this a while back. Pretty clever, it's one of those things that seems obvious once you learn of it. Quote: For a method to take place like this, what is the point of disabling JS. Even if you disable it and think you're safe, your personal information is still in a risk situation.JS is totally different. This CSS method is only dangerous when used as XSS or if used in Stylish/Stylus. With JS, real exploits can be used, like in the case of Spectre (which was patched by making JS' timing functions less accurate). With this, there isn't as much risk. RE: CSS keylogger - Vultra - 07-22-2018 (07-22-2018, 03:17 AM)Ender Wrote: Saw this a while back. Pretty clever, it's one of those things that seems obvious once you learn of it. Oh for sure on your statement. It's honestly shocking to hear since, Most people wouldn't know about this due to what CSS is. RE: CSS keylogger - Blink - 07-22-2018 (07-22-2018, 03:27 AM)Mimiakira Wrote:(07-22-2018, 03:17 AM)Ender Wrote: Saw this a while back. Pretty clever, it's one of those things that seems obvious once you learn of it. (un)Surprisingly enough, CSS with HTML is Turing complete: https://github.com/elitheeli/stupid-machines/tree/master/rule110 RE: CSS keylogger - mothered - 07-22-2018 (07-22-2018, 03:17 AM)Ender Wrote: JS is totally different. This ^^ Different and effective In It's own way. It can obtain your location, connection type (Inclusive of ISP, Internal & External IPs), login account type, hardware specs, OS, browser type & version, timezone and the list goes on- all without permission nor any Input from the end user. Collectively, an Identity can be built from the ground up. RE: CSS keylogger - Vultra - 07-22-2018 (07-22-2018, 03:43 AM)mothered Wrote:(07-22-2018, 03:17 AM)Ender Wrote: JS is totally different. I partially forgot about that. My head was on the other side. From that being said, that clears that up on the behalf of my post with JS being "pointless". RE: CSS keylogger - mothered - 07-22-2018 (07-22-2018, 03:50 AM)Mimiakira Wrote:(07-22-2018, 03:43 AM)mothered Wrote:(07-22-2018, 03:17 AM)Ender Wrote: JS is totally different. No problem whatsoever. JavaScript can be very dangerous when used for malicious Intent. All the above can be achieved by simply "viewing" a webpage, without generating a single click of the mouse. |