lol its ether phishing or MITM attack (Man-in-the-Middle) and injecting html-js into the other guy responses. since you say it was on the same network its most likely MITM , there are many tools around to do it :) just google it… i even remember there was a cool app for android think it was dsploit , adn you could inject javascript into the http responses of any user in the network , it was really funny to see people around getting freak out by just injecting