JSFiddle - React, Tailwind, and code Playground
HTML
<script src="https://cdnjs.cloudflare.com/ajax/libs/async/0.9.0/async.min.js"></script>
<div class="supernaive">
<h3>SUPER naive stealer (triggers)</h3>
<form action="/" onsubmit="return window.stolen(window);">
<label>Login: <input type="text" id="login" /></label><br />
<label>Password: <input type="password" id="password" /></label><br />
<input type="submit" value="Steal your info" />
</form>
</div>
CSS
iframe {
padding: 0.25em;
margin: 0.25em;
width: 100%;
border: 1px black solid;
display: none;
}
.supernaive {
padding: 0.25em;
margin: 0.25em;
border: 1px black solid;
}
iframe.naive {
display: block;
}
body {
margin: 0;
padding: 0;
}
JavaScript
window.stolen = function(win) {
alert('Stolen!\n\nLogin: "' + win.document.getElementById('login').value +
'"\nPassword: "' + win.document.getElementById('password').value + '"');
return false;
};
function createFrame(title, cb) {
var source = (function(){/*
<html>
<body>
<h3>{{TITLE}}</h3>
<form action="/" onsubmit="return window.parent.stolen(window);">
<label>Login: <input type="text" id="login" /></label><br />
<label>Password: <input type="password" id="password" /></label><br />
<input type="submit" value="Steal your info" />
</form>
</body>
</html>
*/}).toString().slice(15,-3);
source = source.replace('{{TITLE}}', title);
var iframe = document.createElement('IFRAME');
iframe.srcdoc = source;
iframe.addEventListener('load', function() {
return cb(null, iframe);
});
document.body.appendChild(iframe);
}
function createFrames(count, cb) {
var i;
var tasks = [];
for (i = 0; i < count; i++) {
(function(i) {
tasks.push(function(cb) {
createFrame('Rotating fishing frame #' + (i + 1) + ' (bypasses)', cb);
});
})(i);
}
async.parallel(tasks, cb);
}
function toggleFrame() {
var loginState = saveInputState('login');
var passwordState = saveInputState('password');
var focusState = saveFocus();
gFrames[masterFrameIdx].style.display = 'none';
masterFrameIdx = (++masterFrameIdx) % gFrames.length;
gFrames[masterFrameIdx].style.display = 'block';
restoreInputState('login', loginState);
restoreInputState('password', passwordState);
restoreFocus(focusState);
}
function saveInputState(id) {
var input = gFrames[masterFrameIdx].contentWindow.document.getElementById(id);
return {
value: input.value,
selectionDirection: input.selectionDirection,
selectionStart: input.selectionStart,
selectionEnd: input.selectionEnd
...