Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
css-the-bomb-inside-your-inbox — All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox. | Kitploit
Tools/GitHubGitHub/portswigger/css-the-bomb-inside-your-inbox
ExploitationWeb Application ExploitationData ExfiltrationWeb SecurityPapers & ResearchLearning & EducationCurated ResourcesPayload DevelopmentEmail Security
AI Security
GitHubportswigger/css-the-bomb-inside-your-inbox

css-the-bomb-inside-your-inbox

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

View Repository
438261 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CSS: the bomb inside your inbox

Repro header

Welcome to the repo. This repository contains all the materials for my talk "CSS: the bomb inside your inbox". This repository contains proof of concept code, test cases, and supporting material that were identified, developed, or collected solely for the purposes of legitimate security research, analysis, and defensive testing. You can read about this research at: Research paper

Table of contents

Pocs

  • CSS hotwiring
  • Exfiltrate tokens on paste
  • Exfiltrate text nodes with CSP blocking external resources
  • HTML only keylogger
  • Prompt injection via email
  • Outlook defacement
  • Outlook Firefox keylogger
  • Outlook label jacking
  • Outlook sanitized keylogger
  • Realtime Chrome keylogger

Tools

  • Shazzer
  • Hackvertor

Proof of concepts

CSS hotwiring

This directory contains the poc for the CSS hotwiring attack on FastMail. The first code snippet shows the plaintext vector without being encoded. The second example is the payload encoded, and it mutates when using the CSSOM is used and the CSS code is read back.

Poc

Exfiltrate tokens via paste

This directory contains the poc demonstrating the attack on Medium using Firefox. It generates the CSS to steal the start, end and middle part of the token. Then copies it to clipboard when the victim clicks the button. I've included the required PHP files needed to retrieve the token parts. The text files need to be writable on the server and the .htaccess file needs to be used in order to extract information from the path.

Poc

Exfiltrate text nodes with CSP blocking external resources

This directory demonstrates the token exfiltration technique to steal text nodes when CSP is blocking external resources. I've included the debugging information to make it clear how it works.

Poc

HTML only keylogger

This demonstrates stealing keystrokes using pure HTML. I use small unicode characters to hide the letters. The marquee is used to cut off the select so it doesn't look like one.

Poc

Prompt injection via email

This poc shows the prompt I used to convince Atlas to get data from the page and exfiltrate it via the URL by opening tabs. You'll notice each URL is in the prompt this is because Atlas seemed to compare the prompt text against URLs it opens to decide if it opens a confirmation prompt.

Poc

Outlook defacement

This contains the poc I used to deface Outlook. "data-tabster" is the HTML attribute needed to for the library to append the CSS gadget to the node when the email is read.

Poc

Outlook Firefox keylogger

This is the exploit on Outlook I demonstrated in my talk. It spoofs the login screen, uses the animation trick to make it real time on Firefox and the label makes the fake input clickable which reproduces the behaviour of the login screen.

Poc

Outlook label jacking

This shows how I used labels to control the UI in Outlook to pin an attackers message to the victim's inbox.

Poc

Outlook sanitized keylogger

Unbelievably I managed to construct a fully working keylogger in sanitized CSS. This uses the CSS gadget to take over the screen. But it has limitations since you did not have full control over the CSS. See the "Outlook Firefox keylogger" for the full version that spoofs the Outlook login screen completely.

Poc

Realtime Chrome keylogger

This poc shows how to use Interest Invokers to create a realtime keylogger in Chrome.

Poc

Tools

CSS token exfiltrate

I created a minimal CSS token exfiltration tool whilst testing Gitlab. You can use this if you have a style injection and recursive CSS imports are allowed.

Tool

Shazzer

Shazzer enabled me to find image proxy bypasses and various CSS quirks and behaviours. I've made my vectors public so you can see how they were discovered. You can view the entire collection of vectors with the following URL:

CSS: the bomb inside your inbox collection

Note:The vectors will be made public after my talk.

Hackvertor

I used Hackvertor to construct the CSS mutations. This was done using the cssEscape tag. Hackvertor also has a "Copy as HTML" feature which creates a blob of your input and places it on the clipboard. This was used to probe sites for CSS injection from paste.

Don't forget to check out the Research paper!

Download Tool