Security: filesystem URLs Spoofing
Reported by
xis...@gmail.com,
Feb 27 2017
|
||||||||
Issue descriptionVULNERABILITY DETAILS When input the following url in address bar filesystem:http://www.hackevil.com@www.example.com, the chrome will display the whole url。 The string in front of "@" may allow a remote attacker to carry out phishing style attacks. VERSION Chrome Version:56.0.2924.87 (64-bit)[Stable] Operating System: Windows7/10 Online Demo: https://jsfiddle.net/xisigr/70Lwst5m/ .Please click "click me" button.
,
Feb 27 2017
Please open it in chrome normal mode. Because filesystem is disable in incognito mode.
,
Feb 27 2017
Thanks, I opened it in normal mode. I don't think there is a security vulnerability here, as it does show that it is a filesystem URL. That being said, we should track this as a feature bug because it brings to mind a few options that could make these dialogs easier to understand for our users: 1) Adding the not secure badge to filesystem URLs 2) Hiding the untrusted part of the URL
,
Feb 27 2017
We are aware of the spoofing risks posed by pseudo URLs such as filesystem. Please see bug 594215 . I agree in this particular case we should probably have dropped the part before @, but I think it's better to solve the problem by doing something more substantial instead (e.g. block navigations to these urls, or simply drop the filesystem scheme and show origin instead or some such)
,
Nov 10 2017
,
Feb 18 2018
,
Apr 27 2018
This may have gotten fixed by Issue 809062 .
,
Apr 27 2018
Issue 809062 has been merged into this issue.
,
Apr 27 2018
Bug 809062 is a duplicate of this one and we decided it's a medium severity security bug, so adding back the labels here. The fix will be bug 811558 .
,
May 4 2018
,
May 14 2018
Hi meacer, is this bug possible to get a reward and CVE number?
,
May 14 2018
Commit 54400200 initially landed in 68.0.3416.0
,
May 21 2018
I'm afraid the VRP panel declined to reward for this bug. Many thanks for the report. It will get a CVE when Chrome 68 goes stable.
,
Oct 2
|
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by kerrnel@chromium.org
, Feb 27 2017Owner: est...@chromium.org
Status: Assigned (was: Unconfirmed)