# Dangling Markup - HTML scriptless injection ## Resume This technique can be use to extract information from a user when an **HTML injection is found**. This is very useful if you **don't find any way to exploit a** [**XSS** ](xss-cross-site-scripting/)but you can **inject some HTML tags**. It is also useful if some **secret is saved in clear text** in the HTML and you want to **exfiltrate** it from the client, or if you want to mislead some script execution. Several techniques commented here can be used to bypass some ****[**Content Security Policy**](content-security-policy-csp-bypass.md) by exfiltrating information in unexpected ways \(html tags, CSS, http-meta tags, forms, base...\). ## Main Applications ### Stealing clear text secrets If you inject `test ``` ### Stealing forms ```markup ``` Then, the forms that send data to path \(like `
`\) will send the data to the malicious domain. ### Stealing forms 2 Set a form header: `` this will overwrite the next form header and all the data from the form will be sent to the attacker. ### Stealing forms 3 The button can change the URL where the information of the form is going to be sent with the attribute "formaction": ```markup