New issue
Advanced search Search tips

Issue 702945 link

Starred by 4 users

Issue metadata

Status: WontFix
Owner:
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Spoofing via alert()

Reported by jackwill...@gmail.com, Mar 19 2017

Issue description

Chrome Canary 59.0.3045.0 - Windows 7

1. Open index.html.
2. Click on attack button.
3. Then type www.google.com and observe.
 
Screen shot.png
54.7 KB View Download
index.html
312 bytes View Download
Summary: Security: Spoofing via alert() (was: Security: Bar URL spoof)
The issue being reported seems to be only that you can show an alert dialog while the URL of the uncommitted navigation remains in the location bar?
Yeah.
Actually I'm not sure if is it a security issue.

Comment 4 by tsepez@chromium.org, Mar 20 2017

Components: UI>Browser>Navigation
Labels: Security_Severity-Low Security_Impact-Stable M-59 OS-All
Owner: nparker@chromium.org
Status: Assigned (was: Unconfirmed)
Seems familiar, but I couldn't find a duplicate entry for this issue.
Cc: a...@chromium.org
Status: WontFix (was: Assigned)
This requires some unusual user action, so I will call it WF.  The same thing happens when you go one site and then type in a different URL w/o committing it.

Comment 6 by creis@chromium.org, Mar 20 2017

Cc: creis@chromium.org
Agreed.  This is one of the reasons the dialog includes "localhost says:", which provides an additional signal of which pages showed it.  (The URL is also something the user just typed, so it's not really under attacker control.)

Comment 7 by mea...@chromium.org, Mar 20 2017

> This requires some unusual user action, so I will call it WF. 

I don't think this is necessarily true. If your site is indexed by google, you can change your main page to display an alert/confirm/prompt dialog on load, and any person coming from google will see the dialog on google.com.

A very shortlived POC because Google reindexes and downgrades the site in about 15 minutes: Search google for "mustafaacer.com" and click on the link. The prompt shows up on google.com.

Comment 8 by creis@chromium.org, Mar 20 2017

Comment 7: When I try that, both the URL bar and the dialog say www.mustafaacer.com.  It is unfortunate that the Google search results stay visible underneath the dialog, but that's kind of the reverse of a URL spoof (i.e., attacker's URL over victim page contents, with correctly labeled dialog).

Comment 9 by mea...@chromium.org, Mar 20 2017

Okay, I thought this was similar to the HTTP auth spoof in  bug 149871  but the omnibox showed incorrect origin in that bug in addition to the dialog. I was about to suggest displaying a blank interstitial here too, but that doesn't seem necessary.
Cc: kenrb@chromium.org lukasza@chromium.org
 Issue 730638  has been merged into this issue.
Project Member

Comment 11 by sheriffbot@chromium.org, Jun 27 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment