User Tools

Site Tools


prevent_lucy_from_collecting_passwords_in_form_submits

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Last revisionBoth sides next revision
prevent_lucy_from_collecting_passwords_in_form_submits [2017/08/21 11:32] lucyprevent_lucy_from_collecting_passwords_in_form_submits [2021/08/12 23:27] lucy
Line 21: Line 21:
  </html>  </html>
  
 +===== Option 2: Do not collect any data =====
 +To exclude the credentials from the POST request one should empty the name attribute of the login and password fields. So the form on index.html will look as follows:
  
-===== Option 2: collect full usernames, but only first three letters of the password =====+  <form action="?login" enctype="application/x-www-form-urlencoded" method="post"> 
 +  <input class="lucy-login-1-text" name="" placeholder="Login" type="text" /><br /> 
 +  <input class="lucy-login-1-text" name="" placeholder="Password" type="password" /><br /> 
 +In that case neither user login nor password will leave the victims browser. 
 + 
 +===== Option 3: collect full usernames, but only first three letters of the password =====
  
 {{ 3letters_.png?600 }} {{ 3letters_.png?600 }}
prevent_lucy_from_collecting_passwords_in_form_submits.txt · Last modified: 2022/04/07 19:59 by lucy