|
|
|
|
|
by matthewarkin
4063 days ago
|
|
Thats basically the concept, once you have malicious js you can replace the iframe with a malicious one that looks the same. You can even have it still create a legitimate card token, so in theory the website would never know they are hacked. The other PCI SAQ A scenario is linking off site. So while malicious JS could change the link you redirect to customers to it would be noticed because the customer may see a sketchy url and the merchant would see a decrease in sales. |
|
Would the next step be to turn of JS at all? Or go back to hosted cc forms only?