Security researcher Dylan Ayrey published a new hacking method last week, called Pastejacking, that uses JavaScript as an attack vector.
The Pastejacking attack works in the same way as an older attack that used CSS, but with JavaScript, which makes it much more effective.
JavaScript is a much more powerful programming language and much more flexible than CSS. With the older method using CSS the user had to copy-paste the entire malicious text, while with Javascript they don't have to select the entire text.
Copying a single character is enough!
Theoretically, an attacker could add a malicious Pastejacking Javascript code from an entire page when pasting even something very small into a terminal. That way, they could run whatever commands they want without anyone noticing.
Dylan Ayrey posted a demo where the attacker runs his malicious code, clears the victim's clipboard, and then adds the code the victim had copied, making them believe nothing happened.
The attack can be very dangerous especially if it is done through technical support pages or phishing emails. Users may think that they are copying code from these sources are innocent, but in reality they are very dangerous exploits.
To test the new, rather sneaky attack, visit the PoC and copy-paste the harmless text into a terminal.
Read more details from the link below:
