Breaking Browsers: Hacking Auto-Complete (All Materials Available)
Essentially I described how a malicious website could steal their visitors names, job title, workplace, physical address, telephone number, email addresses, usernames, passwords, search terms, social security numbers, credit card numbers, and on and on by manipulating a Web browsers HTML form auto-complete / autofill functionality. For good measure I also showed show a Web page could evict all of a users cookies thereby automatically logging users out of all their current sessions, delete tracking cookies, and so on. Lastly, with only clever bits of of javascript, these attacks impact millions of Web users cheaply via online advertising networks. Yes, a lot of fun.
My complete “Breaking Browsers: Hacking Auto-Complete” slide deck is available. I’ve put up a series of blog posts describing each of the distinct Web hacking techniques complete with proof-of-concept code, screen shots, videos, and technical explanations. Enjoy!
- Safari v4/v5 AutoFill Web form vulnerability (CVE-ID: CVE-2010-1796)
- Internet Explorer 6 & 7 stealing AutoComplete form data
- Firefox mass spoofing form auto-complete data
- Stealing passwords out of the Firefox and Chrome password manager using XSS.
- Cookie Eviction - Deleting ALL of a users cookies across ALL websites
Other closely related Auto-Complete / AutoFill bugs:
No comments:
Post a Comment