New issue
Advanced search Search tips

Issue 661006 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

I see a warning in the DevTools about "Self-xss"?

Reported by cmarkta...@gmail.com, Nov 1 2016

Issue description

VULNERABILITY DETAILS
I received a warning on my console that my google account was prone to an attack called self xss. I noticed that my google account has this ?utm_source=OGB&pli=1
This facebook app can compromise a user's facebook account. 

VERSION
Chrome Version: [54.0.2840.71 64bit] + [stable, beta, or dev]
Operating System: [Windows7 64bit]

REPRODUCTION CASE
https://www.google.com.ph/url?sa=t&rct=j&q=&esrc=s&source=web&cd=4&cad=rja&uact=8&ved=0ahUKEwiqlbXjmIbQAhWqJ8AKHXemCbMQFggpMAM&url=http%3A%2F%2Fwww.smartapproach.n.nu%2F&usg=AFQjCNGkJxwYj5MzVEu75QegIovJY6p64A&sig2=7jAWuH-fdW-LlMgMKArFmQ

https://staticxx.facebook.com/connect/xd_arbiter/r/fTmIQU3LxvB.js?version=42#
https://www.facebook.com/l.php?u=http%3A%2F%2Fon.fb.me%2F1mXNHhm&h=6AQFDyZra&s=1

redirects to another site  http://on.fb.me/1mXNHhm


 
Facebook.jpg
85.7 KB View Download
fb redirects.jpg
153 KB View Download

Comment 2 by ta...@google.com, Nov 1 2016

Labels: Needs-Feedback
I'm not sure I understand the problem.

http://on.fb.me/1mXNHhm redirecting to a facebook webpage seems correct to me.

Could you elaborate more about self xss? Thanks.


self xss google account.jpg
169 KB View Download
Allow me to improve my report. 
Cross-origin attacks work by using CSS style sheets from vulnerable pages and extracting sensitive information from these pages in the form of css property attributes.

Reproduction Cases:
1.http://www.smartapproach.n.nu/ it shows an error refused to display there was a link on indicated it is the url below.

2.https://www.facebook.com/l.php?u=http%3A%2F%2Fon.fb.me%2F1mXNHhm&h=6AQFDyZra&s=1

This means that I followed a link in facebook that redirects me to another site 

3.http://on.fb.me/1mXNHhm

This is another vulnerability I noticed that there was an error on my console. I discovered that google accounts are vulnerable to self xss. 
Self Xss is a social engineering attack used to gain control of victim's web accounts in a self xss attack, the victim of the attack accidentally runs malicious code on his/her web browser, thus exposing it to attacker.

https://myaccount.google.com/?pli=1
Status: WontFix (was: Unconfirmed)
Summary: I see a warning in the DevTools about "Self-xss"? (was: Privacy)
This is working as intended.

The Website is warning the user that they may be tricked into doing something dangerous if they're using the Console, as the developer tools console allows the user to execute dangerous script that exposes the content of the page to another site.
Project Member

Comment 6 by sheriffbot@chromium.org, Feb 8 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment