Collected research
Automated Password Extraction Attack on Modern Password Managers
[1309.1416] Automated Password Extraction Attack on Modern Password Managers
Lupin makes a browser's own password manager give up saved credentials: a network attacker injects a login form into any non-HTTPS page and the manager autofills it, including passwords for sites the victim is not visiting and forms whose destination is HTTPS. A crawl of the Alexa top 45,000 found at least 28% vulnerable, and Lupin pulled passwords from 1,000 sites in under 35 seconds.
Record
- Document
- [1309.1416] Automated Password Extraction Attack on Modern Password Managers
- Researcher
- Raul Gonzalez, Eric Y. Chen and Collin Jackson
- Published by
- arXiv.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Raul Gonzalez, Eric Y. Chen and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .