Hacker News new | ask | show | jobs
by sejit 4105 days ago
The source has changed since your post. If I use LastPass and visited the site, should I be worried? What did the script do?
1 comments

The script grabbed document.documentElement.innerHTML and resubmitted it as the new page contents. See my post above regarding CSRF.