I was on some website the other day and I opened the browser console for unrelated reasons. They had a giant message there that was like “STOP. If someone asked you to paste something here, you are probably going to be hacked. Do not do anything here unless you know what you’re doing.”
Which, admittedly, is probably good advice.
Good thing the site is asking me for pressing ctrl and v instead of pasting.
I’ve seen that before. I think it s default for some js package
I think Facebook started doing that 15 years go. Lots of people were being scammed like that.
I don’t get it, how does that hack/scam work?
Someone would say something like ‘you can unlock a secret page on Facebook, just press F12 and paste this in’, and the snippet would upload the victim’s session token to the scammer’s server. So that they can use the account to promote a crypto scam or whatever.
If you paste code into the consol the code writer can do anything you can do on any website in the context of the current website you are on. So for example download files, capture any data, or take over and use your active session remotely.
I’ve opened console on some random site with far too wide article text and those asshats froze my whole browser.
(() => "I'm in.")()Tried to 1-up you and ended up on a list

Well… That’s kinda terrifying
Wait, why does it think this is looking for child porn? Do I even want to know?
JS in Japan can mean elementary schoolgirls.
But I swear Google used to be smarter than this. It’s the training data from 4chan that poisoned it’s mind, surely.
Inguess we will all have to switch to TypeScript to search up JS stuff now. What comes up for “TS Fuck”
Reminds me of when my VP of engineering told me to be careful when trying to get to the TypeScript Playground. Googling “ts playground” brought him to a site that was absolutely not safe for work.
must be saying something about JS programmers
...
mandatory /s
I have no idea and at this point I’m too afraid to ask
Why do you use Google?
Because it’s baked into my phone. I get what I deserve, honestly.
I don’t see a CVE for this anywhere. Security folks must be asleep at the wheel /s
I got hacked by pressing F12 then Ctrl+v

Hacking is easy, indeed.
Mooooom, I’ve been hacked!
I'm in.





