New issue
Advanced search Search tips

Issue 769314 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Open Redirection Vulnerability

Reported by sexypran...@gmail.com, Sep 27 2017

Issue description

Hello I found that in Chrome web application, I am able to exploit the system of "username:password@hostname" as a form of authentication to create a redirect. 

There is no alert or notification while exploiting this mechanism. 

While I notice in other browsers such as mozilla firefox, IE explorer, There is a proper alert while redirecting as you can see in attached screenshots.

Procedure to exploit:-
1- Visit the below URL: 
 http://blog.slicepay.in%2f2017%2f09%2f20%2fapply-win-contest@google.com
2- If the above URL is opened in chrome browser then it'll be redirected to google.com without any notification, But in other browsers it'll show an alert.

Attached files:-
1- Screenshot of IE explorer of alert
2-Screenshot of mozilla firefox
3-POC video of webpage opened in google chrome and it was redirected to any other webpage.
Kindly Reply!!
 
mozilla.JPG
116 KB View Download
microsoft(POC).mp4
432 KB View Download
IEexplorer.JPG
106 KB View Download
Status: WontFix (was: Unconfirmed)
Not a security vulnerability, this is how web works. Most web sites don't support http authentication via username:password as well.
Thanks for your reply.first of all it works for both http as well as https and secondly this is not a website issue because I can change blog.slicepay.in to anything.com. This issue is equivqlent to open redirect vulnerability and any website is vulnerable to this because of the web browser. The same can't be done on other browsers as they throw an error which clearly states that this might be done to trick the victim(check image). Hacker can successfully redirect user to any website by taking advantage of this vulberability on google chrome. I hope i have explained everyrhing clearly.
Project Member

Comment 3 by sheriffbot@chromium.org, Jan 4 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment