Other nomination
Google Chrome HTTP AUTH Dialog Spoofing through Realm Manipulation
Chrome through 5.0.375.127 does not scrutinise the realm value of a WWW-Authenticate header, so quotes placed inside it let an attacker control what the HTTP auth dialog displays and spoof which site is asking for credentials. Combined with Chrome not showing the real domain for obfuscated redirects, it supports credential phishing.
Record
- Researcher
- Aditya K Sood
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host.