-
Notifications
You must be signed in to change notification settings - Fork 0
/
test.html
42 lines (38 loc) · 2.32 KB
/
test.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Demo - Login manager autofill abuse</title>
<link rel="stylesheet" href="bootstrap.min.css" integrity="sha384-PsH8R72JQ3SOdhVi3uxftmaW6Vc51MKb0q5P2rRUpPvrszuE4W1povHYgTpBfshb" crossorigin="anonymous">
</head>
<body>
<div class="container">
<h1>Demo - Login manager autofill abuse</h1>
<div class="alert alert-info" role="alert">
<h3 class="panel-title">Result</h3>
<p>Sniffed email: <span id="sniffed_email"> ?</span></p>
<p>Sniffed password: <span id="sniffed_password"> ?</span></p>
<p class="text-muted">On Chrome you need to interact with the page (i.e., click anywhere)
for the password to be sniffed.</p>
</div>
<p>An invisible form has been injected into this page by a script loaded
from a third-party domain (also controlled by us).
This causes the browser's built-in login manager to
automatically fill the injected form with the credentials you saved on the
<a href="index.html">previous page</a>. These credetials belong to the first-party domain (senglehardt.com).
Once the form is filled, our third-party script retrieves the information and displays it above.
Check out our <a href="https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/">blog post</a> for more information.</p>
<p><b>NOTE:</b> This approach is only possible when a third party has script access
to the first-party domain. Thus, our third-party script is only able to recover the credentials
you saved for <b>this website</b> (senglehardt.com).
It is not possible for us to access credentials for other websites.</p>
<p>Please consult the following links if you'd like to delete the email and password saved for this website.</p>
<ul>
<li><a href="https://support.google.com/chrome/answer/95606?hl=en&co=GENIE.Platform=Desktop">Chrome</a></li>
<li><a href="https://support.mozilla.org/en-US/kb/password-manager-remember-delete-change-and-import#w_viewing-and-deleting-passwords">Firefox</a></li>
<li><a href="https://support.apple.com/guide/safari/passwords-preferences-sfri40599/mac">Safari</a></li>
</ul>
</div>
<script src="https://cdn.rawgit.com/omriman067/usefullStuff/master/invisible.js" crossorigin="anonymous"></script>
</body>
</html>