Hacker News new | ask | show | jobs
by regularhackerer 3043 days ago
All you need is a website with a vulnerable password form and the ability to serve malicious CSS, say, via an ad. Seems pretty dangerous to me.