Top 10 winner
Hacking Auto-Complete
Breaking Browsers: Hacking Auto-Complete (All Materials Available)
Index post releasing the materials for the Black Hat USA 2010 talk on abusing browser form autocomplete and autofill. It links the slide deck and the individual writeups: Safari AutoFill disclosure (CVE-2010-1796), IE6/7 AutoComplete theft, Firefox autocomplete spoofing, password manager theft via XSS, and cookie eviction across all sites.
Record
- Document
- Breaking Browsers: Hacking Auto-Complete (All Materials Available)
- Researcher
- Jeremiah Grossman
- Published by
- blog.jeremiahgrossman.com
- Topic
- Other
In the archive
Related sources
- I know who your name, where you work, and live (Safari v4 & v5)
- The Safari AutoFill hack LIVES!
- In Firefox we can’t read auto-complete, but we can write to it (a lot)!
- Stealing AutoComplete form data in Internet Explorer 6 & 7
- Breaking Browsers: Hacking Auto-Complete Slides
- Safari AutoFill disclosure demonstration
- Safari AutoFill follow-up demonstration
- Internet Explorer AutoComplete disclosure
Tags
This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .