./D Wrote:
-------------------------------------------------------
> Actually, I'm nearly positive that the hidden
> input type can't take focus, so onfocus wouldn't
> work.
Confirmed, my mistake. It feels like there should still be a way to exploit this without much/any user interaction, but I can't see how.
-------------------------------------------------------
Research blog