Hacker News new | ask | show | jobs
by alptrv 4945 days ago
I think you need to update your post with the clarification that you don't have to add XSS directly to the login page - you can steal user's password from whatever page the user are currently in, even if they are already logged in.
1 comments

that's right. i thought it's obvious - will update