What is a cross-site script? This is called (XSS) in the tongue of hackers.This attack is a browser-based attack, nowadays it is not used much by hackers as it is an old method.
But this cannot be taken at all this method is over and is not being used
This attack is still alive and has been done to it with some new appreciation, believe me even today a hacker can make you richer to poorer.
Let's learn how it works:
For example, if you have an account on MyEtherWallet and this website is vulnerable for this attack, then any person will be logged in with the private key, All his data will go to Attaker, if there is an exchange website, then you can have your login data, once again there is a another benefit of 2FA.
If seen, there is no mistake of the user here, this is due to the failure of the website owner.
To do this attack, the hacker has to do more than just scan when he finds his target.
he adds a script through a JavaScript, just whoever logs in will hand over the entire data to Attacker, Once this happened, the hacker (Attacker) would take advantage of this detail, now either he will sell it to someone or he will steal money or crypto himself.
This is a kind of keylogger, Meaning whatever letter you wrote with your keyboard will go to Attacker.
You should know that any website is weak for some time but by that time, the hacker collects a lot of data.
Please note: it works on only one website, meaning if the MyEtherWallet is hacked, only its data will go to Attaker, This is the reason it is called browser based attack.
This is the code that can cause all this:
![](https://ip.bitcointalk.org/?u=https%3A%2F%2Fi.ibb.co%2FP427rpZ%2F20200217-122921.png&t=671&c=GPSzwia_i4yPVw)
This script was actually found by a security researcher, but the hackers are taking advantage
How do you avoid this? You cannot scan every website every time, right? So the solution to all this is that you use 2FA, that's all you can do.
Do not login with private keys. And the website owner should keep checking their website.
If you have read my entire post, then Shukria
Script author: İsmail Taşdelen
Author website:
http://ismailtasdelen.com/