Web Hack List

Collected research

Automated Password Extraction Attack on Modern Password Managers

[1309.1416] Automated Password Extraction Attack on Modern Password Managers

Lupin makes a browser's own password manager give up saved credentials: a network attacker injects a login form into any non-HTTPS page and the manager autofills it, including passwords for sites the victim is not visiting and forms whose destination is HTTPS. A crawl of the Alexa top 45,000 found at least 28% vulnerable, and Lupin pulled passwords from 1,000 sites in under 35 seconds.

Record

Document
[1309.1416] Automated Password Extraction Attack on Modern Password Managers
Researcher
Raul Gonzalez, Eric Y. Chen and Collin Jackson
Published by
arXiv.org
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Raul Gonzalez, Eric Y. Chen and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .