cssInjection

CSS hijacking attack

A method to steal sensitive data by exploiting CSS injection vulnerabilities in websites that allow arbitrary CSS rendering.

Stealing CSRF tokens with CSS injection (without iFrames)

GitHub

318 stars
15 watching
48 forks
Language: HTML
last commit: over 8 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
demi6od/smashing_the_browserAn in-depth exploration of browser exploitation techniques and vulnerability discovery446
dragokas/hijackthisScans for and identifies malicious system modifications704
justinas/nosurfProtects against Cross-Site Request Forgery (CSRF) attacks in web applications by verifying user input1,603
marco-prontera/vite-plugin-css-injected-by-jsA Vite plugin that injects CSS into HTML pages using JavaScript432
heydon/revenge.cssA CSS-based tool that highlights bad HTML markup on web pages842
pillarjs/understanding-csrfAn explanation of how CSRF attacks work and how to mitigate them in web applications.1,402
myfavshrimp/turfA toolchain for compile-time SCSS transformation and CSS injection into binaries68
fuzzysecurity/sharp-suiteA toolset for threat emulation and code injection using C#.1,117
directdefense/superserialA Burp Suite Extender to identify Java Deserialization vulnerabilities in client requests and server responses.9
nachiketrathod/http.request.smuggling.desync.attackAn attacker exploits HTTP request smuggling to manipulate the sequence of requests and deceive both front-end and back-end security controls.14
koajs/stateless-csrfProtects against cross-site request forgery attacks by hashing and verifying user cookies on each request.16
leovoel/beautifuldiscordA tool that injects custom CSS into Discord's desktop application699
syssec-kaist/sigover_injectorA tool that exploits weaknesses in LTE broadcast signals to inject manipulated signals without an FBS.90
ah8r/csrfA tool to scan websites for Cross-Site Request Forgery (CSRF) vulnerabilities and provide protection in Burp Suite Pro.19
tinyhttp/malibuMiddleware to help prevent cross-site request forgery attacks in web applications124