Collected research
Google Chrome HTTP AUTH Dialog Spoofing through Realm Manipulation
User Interface Security - Google Chrome HTTP AUTH Dialog Spoofing through Realm Manipulation
Chrome through 5.0.375.127 does not scrutinise the realm value of a WWW-Authenticate header, so quotes placed inside it let an attacker control what the HTTP auth dialog displays and spoof which site is asking for credentials. Combined with Chrome not showing the real domain for obfuscated redirects, it supports credential phishing.
Record
- Document
- User Interface Security - Google Chrome HTTP AUTH Dialog Spoofing through Realm Manipulation
- Researcher
- Aditya K Sood
- Published by
- zeroknock.blogspot.com
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .