⚠ DEMO 06 — Drag-and-Drop Exfiltration | Authorized research only

DRAG-AND-DROP EXFILTRATION

DRAG API · DATA THEFT

Sensitive data (API keys, PII) rendered as draggable text. Attacker drop zone captures dragged content via drag/drop events — exfiltrating without copy/paste awareness.

[ DRAG SECRET → DROP ZONE ]
Internal Dashboard

Your API key (drag to share with team):

sk-live-4eC39HqLyjWDarjtT1zdp7dc
📁 Team Share Zone
Drop file here to share
[*] Drag the API key to the drop zone...
Real attacks: Used against webmail, admin panels. Defense: disable draggable on sensitive elements, CSP.