I’m harvesting credit card numbers and passwords from your site. Here’s how.
Posted by jpluimers on 2020/01/14
Below is one of the reasons I try to stay on the back-end side of things. Those are complex enough to focus on for me.
[WayBack] I’m harvesting credit card numbers and passwords from your site. Here’s how.
It basically comes down to:
- anything in the same page has access to anything happening on that page.
- be careful when using
npmand ad networks. - perform security operations in a light-weight iframe that is scrutinized.
The source of any npm package might be different from the source you find in a the underlying repository. This recursively holds for all the other npmit pulls in.
–jeroen






Leave a comment