Web Hack List

Collected research

Google Chrome HTTP AUTH Dialog Spoofing through Realm Manipulation

User Interface Security - Google Chrome HTTP AUTH Dialog Spoofing through Realm Manipulation

Chrome through 5.0.375.127 does not scrutinise the realm value of a WWW-Authenticate header, so quotes placed inside it let an attacker control what the HTTP auth dialog displays and spoof which site is asking for credentials. Combined with Chrome not showing the real domain for obfuscated redirects, it supports credential phishing.

Record

Document
User Interface Security - Google Chrome HTTP AUTH Dialog Spoofing through Realm Manipulation
Researcher
Aditya K Sood
Published by
zeroknock.blogspot.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .