New issue
Advanced search Search tips

Issue 594098 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Able to see my password

Reported by uspsam...@gmail.com, Mar 11 2016

Issue description

This template is ONLY for reporting security bugs. Please use a different
template for other types of bug reports.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs


VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.
Able to see my login password with Developer tools.


VERSION
Chrome Version: [49.0.2623.87] + [stable, beta, or dev]
Operating System: [Windows 7]

REPRODUCTION CASE
Steps to Reproduce
1. Go to facebook login page 
2. Enter your credentials
3. Open developer tools(Press F12 in Google Chrome)
4. Navigate to Network Tab in Developer Tools window
5. Check Preserve Log
6. Click on Login in Facebook.
7. Verify the results in Network tab. Filter login.php, verify the header - form data.
8. I am able to see my password in the form data.


FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
Issue.PNG
174 KB View Download
Status: WontFix (was: Unconfirmed)
This is how the web works. You can see your own network requests sent from your browser client in dev tools.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 18 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment