Reveal LastPass shared site passwords

So you want to share a site with your co-worker, but don’t want them to have the password. Unfortunately, you’re out of luck if they have heard of javascript.

Step 1: Share a LastPass site without password view permissions

LP_Blog_1

 

Step 2: Recipient opens their e-mail to accept the shared site

LP_Blog_2.png

Step 3: Recipient goes to their lastpass vault to find the shared credentials

LP_Blog_3.png

Step 4: Recipient uses jquery to find cleartext password

$(‘#siteDialogPassword’).value

…but it is in an iframe. If you got this far, I’ll leave the rest to you.

Advertisements
Reveal LastPass shared site passwords