4 ms·
Any idea how the attacker manages to inject their JavaScript code?
by opinologo 6y ago
Any idea how the attacker manages to inject their JavaScript code?
- bagacrap 6y agoSounds like it's likely coming from a browser extension because they called it "client side".
- lowcodetv 6y ago"The skimmer injects a loader into the page source as an inline script." "Given the obfuscated nature and supply chain origination of in-browser attacks, traditional CSP-reliant approaches miss most of these types of attacks." "Also, a lot of CSP policies don't limit WebSockets usage." ...But CSP is very aggressive with denying inline scripts. Could be a browser plugin, or maybe an infected common JS package?
- hn_throwaway_99 6y agoMy reaction exactly. This whole post seemed like purely thrown shade against CSP, which should prevent both injection and data exfiltration as designed when used correctly, in order to sell Akamai's product.