Jorian @jorianwoltjer.com · Sep 16

On our attacker's page, we load this in an iframe and can then access [0] to get a reference to our injected object. To read its name, we can set its location to *our* about:blank and then read the .name window property (set by the attribute)!

1 likes 2 replies

?

Replies

Turkey Dancer · Sep 16

So this alerts the content of the form?

Jorian · Sep 16

Forgot to add what we leak, this is the result: