New issue
Advanced search Search tips

Issue 622698 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Aug 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Security



Sign in to add a comment

"javascript:" scheme => bypass content type & content spoofing

Reported by ad...@devilteam.pl, Jun 23 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36

Steps to reproduce the problem:
Go to:
https://kacperrybczynski.com/research/chrome_firefox_javascript_scheme/poc/

Check the PoC source and run examples.

What is the expected behavior?
On safari and edge nothing happens. I expect the same on chrome.

What went wrong?
1. Bypass on content-type
2. Content spoofing

Did this work before? N/A 

Chrome version: 51.0.2704.103  Channel: stable
OS Version: OS X 10.11.5
Flash Version: Shockwave Flash 22.0 r0
 
Owner: tsepez@chromium.org
Status: Assigned (was: Unconfirmed)
+tsepez: I think this is a XSS filter bypass using obfuscated Javascript, and thus not considered a security issue. Can you please take a look and confirm?
Components: Blink>SecurityFeature
Labels: Security_Severity-Low Security_Impact-Stable
Tentatively assigning security labels.
Status: WontFix (was: Assigned)
Well, no.  There's a dubious assumption that the js conversion site referenced by that page is producing an exact translation of the first link, which doesn't parse as JS due to the intervening HTML characters.  Since it doesn't parse as JS in the first place, I'm not sure how the translation could be accurate, or how the site recovers from such errors.

There's nothing here about content-type or spoofing.
The JS is contained in the page text itself, not part of the original URLs, so there isn't a reflected XSS, hence not an XSS filter bypass.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 15 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment