New issue
Advanced search Search tips

Issue 821282 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Open redirection

Reported by jishnu.p...@gmail.com, Mar 13 2018

Issue description

Attack scenario:
Google Chrome is one of the most popular browser in the world..Chrome has a lot of advantages, it prevents most of the XSS attacks..but here i describe a open redirection vulnerability in chrome..an attacker can redirect any website by putting just an @anotherdomain.com symbol at end of the domain.. 
eg: https://www.facebook.com@youtube.com , then it will be directly redirect to youtube.com.therfore an attacker can inject malicious code and rediect any website directly using Chrome..but if we put @anotherdomain.com symbol in other browsers it will pop-up a dialogue box to user's to take decisions that is they want to redirect or not..but chrome does'nt pop-up a dialgoue box...it will directly redirect..
Browser/OS: Google Chrome/Windows 

Steps to reproduce:
  
Open Google Chrome,then search anything we want...here i open facebook.. https://www.facebook.com, then type @anotherdomain.com for eg: https://www.facebook.com@youtube.com

Then it will directly redirected to youtube without any warning..but most of the other browsers pop-up a dialogue box to prevent the redirect 

I included a video(poc) to reproduce the issue. I uploaded the poc video in my google drive and the google drive link is

 https://drive.google.com/open?id=148ucXkUsYbyZQlHb5F_5LaIiLmsqIPtZ
 
 
Status: WontFix (was: Unconfirmed)
Thanks for the report.

This is a feature of URLs (user@domain.com), and is not considered a security vulnerability at this time. Note that the part before the @ is not shown to the user after navigation completes. For more information, see the Security FAQ (specifically https://www.chromium.org/Home/chromium-security/security-faq#TOC-Is-Chrome-s-support-for-userinfo-in-HTTP-URLs-e.g.-http:-user:password-example.com-considered-a-vulnerability-)
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 19 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
 Issue 821278  has been merged into this issue.

Sign in to add a comment