⚠ DEMO 08 — Form Action Hijacking | Authorized research only
FORM ACTION HIJACKING
RUNTIME MUTATION · CREDENTIAL THEFT
Form initially posts to legitimate endpoint. Attacker JavaScript mutates action/method
before submit — credentials sent to attacker server while UI appears unchanged.
[ SUBMIT LOGIN FORM ]
[*] Form action is legitimate. Click hijack then submit.