This is a DOM based XSS in Kerio Control 9.3.0 build 3273 auth page.
Yes we can steal cookies and overtake sessions, but i wanted to
demonstrate a different attack which yields credentials in cleartext.
Note:
---------
This is NOT a regular phishing attack, phishing attacks use fake URLs
or Hosts to trick the user into thinking he is visiting the correct page.
In this scenario though, we are using the DOM based XSS to overtake
control of the login forms input fields which the attacker then can read
from, and NO fake URL or fake is required, the attack happens on the
vulnerable Kerio device.