3 ms·
Not an efficient keylogger, however, if you know the pressed keys, you can just generate permutations ordered using probabilities, and that would be a lot faste
by Francute 9y ago
Not an efficient keylogger, however, if you know the pressed keys, you can just generate permutations ordered using probabilities, and that would be a lot faster than brute force.
The real deal here is, it depends on some js code updating the dom for each key press, which is BAAAD. Not an useless keylogger, because it reminds a vulnerability product of choosing a bad decision.
- X-Istence 9y ago> it depends on some js code updating the dom for each key press Like React with JSX?
- tmerse 9y agoIt may be easier to XSS CSS than JS.
- netsharc 9y agoInterestingly the password "BAAAD" would generate 3 requests to the logging server, since it wouldn't request the background image for the letter "A" more than one time. Or shouldn't, anyway.
- early 9y agoThat depends on cache headers sent from the server, which the attacker controls