Collected research
Chrome and Safari users open to stealth HTML5 AppCache attack
Chrome and Safari let any site create an HTML5 Application Cache without prompting, and unlike ordinary cache it can hold a site's root resource. On a hostile Wi-Fi an attacker frames http://mail.google.com/mail/ and caches a fake Gmail login for it, so credentials are stolen later on a trusted network. Pointing the manifest at an existing file keeps the poisoned entry alive.
Record
- Researcher
- lava
- Published by
- blog.andlabs.org
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .