All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

Welcome to the repo. This repository contains all the materials for my talk "CSS: the bomb inside your inbox". This repository contains proof of concept code, test cases, and supporting material that were identified, developed, or collected solely for the purposes of legitimate security research, analysis, and defensive testing. You can read about this research at: Research paper
This directory contains the poc for the CSS hotwiring attack on FastMail. The first code snippet shows the plaintext vector without being encoded. The second example is the payload encoded, and it mutates when using the CSSOM is used and the CSS code is read back.
This directory contains the poc demonstrating the attack on Medium using Firefox. It generates the CSS to steal the start, end and middle part of the token. Then copies it to clipboard when the victim clicks the button. I've included the required PHP files needed to retrieve the token parts. The text files need to be writable on the server and the .htaccess file needs to be used in order to extract information from the path.
This directory demonstrates the token exfiltration technique to steal text nodes when CSP is blocking external resources. I've included the debugging information to make it clear how it works.
This demonstrates stealing keystrokes using pure HTML. I use small unicode characters to hide the letters. The marquee is used to cut off the select so it doesn't look like one.
This poc shows the prompt I used to convince Atlas to get data from the page and exfiltrate it via the URL by opening tabs. You'll notice each URL is in the prompt this is because Atlas seemed to compare the prompt text against URLs it opens to decide if it opens a confirmation prompt.
This contains the poc I used to deface Outlook. "data-tabster" is the HTML attribute needed to for the library to append the CSS gadget to the node when the email is read.
This is the exploit on Outlook I demonstrated in my talk. It spoofs the login screen, uses the animation trick to make it real time on Firefox and the label makes the fake input clickable which reproduces the behaviour of the login screen.
This shows how I used labels to control the UI in Outlook to pin an attackers message to the victim's inbox.
Unbelievably I managed to construct a fully working keylogger in sanitized CSS. This uses the CSS gadget to take over the screen. But it has limitations since you did not have full control over the CSS. See the "Outlook Firefox keylogger" for the full version that spoofs the Outlook login screen completely.
This poc shows how to use Interest Invokers to create a realtime keylogger in Chrome.
I created a minimal CSS token exfiltration tool whilst testing Gitlab. You can use this if you have a style injection and recursive CSS imports are allowed.
Shazzer enabled me to find image proxy bypasses and various CSS quirks and behaviours. I've made my vectors public so you can see how they were discovered. You can view the entire collection of vectors with the following URL:
CSS: the bomb inside your inbox collection
Note:The vectors will be made public after my talk.
I used Hackvertor to construct the CSS mutations. This was done using the cssEscape tag. Hackvertor also has a "Copy as HTML" feature which creates a blob of your input and places it on the clipboard. This was used to probe sites for CSS injection from paste.
Don't forget to check out the Research paper!