Victim of ARP/MITM, want to know how

Chat room, the attacker pulled my IP and was able to view what I was doing and stole a lot of personal information including social media accounts. How was someone able to pull my IP without me clicking on anything? The website has HTTPS. Turns out having a VPN stops them from being able to snoop any further. I want to make it my mission to do the same but for the sake of telling people to use a VPN and protect them from this user who likely does it to everyone in said chat room. There's more people like that on that website and I want to kill the pleasure they get out of it until they absolutely leave the site. The site doesn't work without JavaScript. One of them already harassed an elderly jewish woman with severe autism out of the site and leaked all her info.

When I look up exploits for the site, it says XSS (Cross Site Scripting).

submitted by /u/SlipperyRedFish
[link] [comments]

from hacking: security in practice https://ift.tt/kvSdCTp

Comments