Web Hack List

Collected research

Google Urchin password theft madness

Google Urchin Password Theft Madness

Google Urchin 5's session.cgi login page takes an unfiltered parameter, giving reflected XSS on 5.6.00r2 through 5.7.03. pagvac shows it is worth more than an alert box: rewrite the form action, or exploit the browser's saved-password autocomplete, waiting 1.5s with setTimeout before shipping the filled username and password to an attacker image URL. Works on Firefox 2.0.0.7, not IE 7.

Record

Document
Google Urchin Password Theft Madness
Researcher
pagvac
Published by
gnucitizen.org
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of pagvac, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .