Tunisian government harvesting usernames and passwords

by Steve Ragan
Excerpt:
Daniel Crowley, Technical Specialist for Core Security, and Rapid7’s Josh Abraham, broke the code down further. Crowley explained that the JavaScript is customized for each site’s login form. It will pull the username and password, and encode it with a weak crypto algorithm.
Source: The Tech Herald











