Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
tocomment
12y ago
0 comments
Share
What I'm not getting is how a running executable can log into a website and initiate a transaction. It won't have your password right? Or is it just a keylogger to catch your password?
undefined | Better HN
0 comments
default
newest
oldest
dariopy
12y ago
Like your regular XSRF, it relies on the user already being logged in some browser tab.
It probabley has a keylogger too.
j
/
k
navigate · click thread line to collapse