Later archive addition
Automated Password Extraction Attack on Modern Password Managers
Lupin makes a browser's own password manager give up saved credentials: a network attacker injects a login form into any non-HTTPS page and the manager autofills it, including passwords for sites the victim is not visiting and forms whose destination is HTTPS. A crawl of the Alexa top 45,000 found at least 28% vulnerable, and Lupin pulled passwords from 1,000 sites in under 35 seconds.
Record
- Researcher
- Raul Gonzalez, Eric Y. Chen and Collin Jackson
- Published by
- arXiv.org
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Raul Gonzalez, Eric Y. Chen and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host.