Collected research
Google Urchin password theft madness
Google Urchin Password Theft Madness
Google Urchin 5's session.cgi login page takes an unfiltered parameter, giving reflected XSS on 5.6.00r2 through 5.7.03. pagvac shows it is worth more than an alert box: rewrite the form action, or exploit the browser's saved-password autocomplete, waiting 1.5s with setTimeout before shipping the filled username and password to an attacker image URL. Works on Firefox 2.0.0.7, not IE 7.
Record
- Document
- Google Urchin Password Theft Madness
- Researcher
- pagvac
- Published by
- gnucitizen.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pagvac, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .