Proof of concept for Darknet Diaries report on Magecart Skimmer
Steps to use (no server needed)
-
Place all file into one directory.
-
visitin index page
-
Fill out forms as if you were checking out
-
Check out
-
Investigate
Steps to use (with simple python server)
go into ccserver folder
-
setup python (3.6)
-
install depencies for environment with "pip install -r reqs.txt"
go into website directory
-
visitin index page
-
Fill out forms as if you were checking out
-
Check out
-
Investigate
Educational Beneits
Host-based signatures - depending how on how the malcious javascript is implemented and the Content Delivery Network compromised, host artifacts can be affected