[Greasemonkey] Patterns

Jeremy Dunck jdunck at gmail.com
Wed Apr 13 02:58:07 EDT 2005


On 4/13/05, Aaron Boodman <zboogs at gmail.com> wrote:
> You don't need to open a window from script to use this approach.
> 
> window.addEventListener("mousedown", function(e) {
>   if (e.target.tagName == "A") {
>     e.target.href = "http://youngpup.net?muahaha-youve-been-yp'd!";
>   }
> }, false);

Hey, this just made me think of a GM "exploit".  Similar to your
citibank example before, you could wire up click events on buttons or
whatnot to submit unexpected buttons.

So you mean to check your balance, and instead initiate a balance
transfer.  It's a stretch, but there's the idea.


More information about the Greasemonkey mailing list