Web Hack List

Collected research

Cross Domain Basic Auth Phishing Tactics

ha.ckers.org web application security lab - Archive » Cross Domain Basic Auth Phishing Tactics

Basic-auth phishing needs no clicked link: an embedded image on a protected domain pops the credential dialog on the page you want to phish. Alex supplies two dialog-spoofing bugs that hide the real host: Opera truncates the hostname after 34 characters and appends an ellipsis, and IE7 shows the Punycode form, so a Cyrillic o in microsoft.de passes.

Record

Document
ha.ckers.org web application security lab - Archive » Cross Domain Basic Auth Phishing Tactics
Published by
ha.ckers.org
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .