I was on some website the other day and I opened the browser console for unrelated reasons. They had a giant message there that was like "STOP. If someone asked you to paste something here, you are probably going to be hacked. Do not do anything here unless you know what you're doing."
Someone would say something like 'you can unlock a secret page on Facebook, just press F12 and paste this in', and the snippet would upload the victim's session token to the scammer's server. So that they can use the account to promote a crypto scam or whatever.
If you paste code into the consol the code writer can do anything you can do on any website in the context of the current website you are on. So for example download files, capture any data, or take over and use your active session remotely.
Reminds me of when my VP of engineering told me to be careful when trying to get to the TypeScript Playground. Googling "ts playground" brought him to a site that was absolutely not safe for work.
32 Comments
HuntressHimbo@lemmy.zip · 39 pts · 157d
I don't see a CVE for this anywhere. Security folks must be asleep at the wheel /s
joyjoy@lemmy.zip · 10 pts · 157d
I got hacked by pressing F12 then Ctrl+v
jtrek@startrek.website · 39 pts · 157d
I was on some website the other day and I opened the browser console for unrelated reasons. They had a giant message there that was like "STOP. If someone asked you to paste something here, you are probably going to be hacked. Do not do anything here unless you know what you're doing."
Which, admittedly, is probably good advice.
abbadon420@sh.itjust.works · 12 pts · 157d
I've seen that before. I think it s default for some js package
dovahking@lemmy.world · 6 pts · 156d
Good thing the site is asking me for pressing ctrl and v instead of pasting.
jol@discuss.tchncs.de · 4 pts · 157d
I think Facebook started doing that 15 years go. Lots of people were being scammed like that.
MonkderVierte@lemmy.zip · 2 pts · 157d
I've opened console on some random site with far too wide article text and those asshats froze my whole browser.
712@discuss.tchncs.de · 1 pts · 157d
I don’t get it, how does that hack/scam work?
SteveTech@aussie.zone · 24 pts · 157d
Someone would say something like 'you can unlock a secret page on Facebook, just press F12 and paste this in', and the snippet would upload the victim's session token to the scammer's server. So that they can use the account to promote a crypto scam or whatever.
Candice_the_elephant@lemmy.world · 4 pts · 157d
If you paste code into the consol the code writer can do anything you can do on any website in the context of the current website you are on. So for example download files, capture any data, or take over and use your active session remotely.
a_non_monotonic_function@lemmy.world · 15 pts · 157d
itkovian@lemmy.world · 11 pts · 157d
Hacking is easy, indeed.
melvisntnormal@feddit.uk · 11 pts · 157d
marduk@lemmy.sdf.org · 29 pts · 157d
Tried to 1-up you and ended up on a list
RamenJunkie@midwest.social · 16 pts · 157d
Wait, why does it think this is looking for child porn? Do I even want to know?
raman_klogius@ani.social · 14 pts · 157d
JS in Japan can mean elementary schoolgirls.
But I swear Google used to be smarter than this. It's the training data from 4chan that poisoned it's mind, surely.
Lumidaub@feddit.org · 3 pts · 156d
How'd they get JS from shougakusei? Or wait, is that like "junior school" or something, to obscure its meaning further?
raman_klogius@ani.social · 4 pts · 155d
The abbreviation takes the form of XY where X is:
And Y is:
Lumidaub@feddit.org · 1 pts · 155d
Ooh okay, I see, thank you. I hope this knowledge will never come in handy.
01189998819991197253@infosec.pub · 3 pts · 156d
Let's be honest. The data from 4chan poisoned all of our minds.
a_non_monotonic_function@lemmy.world · 1 pts · 155d
Nope. Never deliberately visited.
RamenJunkie@midwest.social · 3 pts · 156d
Inguess we will all have to switch to TypeScript to search up JS stuff now. What comes up for "TS Fuck"
melvisntnormal@feddit.uk · 3 pts · 156d
Reminds me of when my VP of engineering told me to be careful when trying to get to the TypeScript Playground. Googling "ts playground" brought him to a site that was absolutely not safe for work.
marduk@lemmy.sdf.org · 5 pts · 157d
I have no idea and at this point I'm too afraid to ask
FEIN@lemmy.world · 4 pts · 157d
must be saying something about JS programmers
::: spoiler ... mandatory /s :::
melvisntnormal@feddit.uk · 3 pts · 156d
Well... That's kinda terrifying
712@discuss.tchncs.de · -1 pts · 157d
Why do you use Google?
marduk@lemmy.sdf.org · 4 pts · 157d
Because it's baked into my phone. I get what I deserve, honestly.
renzhexiangjiao@piefed.blahaj.zone · 2 pts · 156d
Tja@programming.dev · 7 pts · 157d
Mooooom, I've been hacked!
MentalEdge@sopuli.xyz · 5 pts · 157d
I'm in.GreenKnight23@lemmy.world · 2 pts · 155d