This isn't really a security issue, it is how URLs work. The value
specified before the "@" is considered to be the username. See RFC 3986.
(https://www.ietf.org/rfc/rfc3986.txt)

That being said, while Chrome simply allows the username, firefox does
display a warning to the user.

** Changed in: webbrowser-app (Ubuntu)
       Status: New => Confirmed

** Information type changed from Private Security to Public

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to webbrowser-app in Ubuntu.
https://bugs.launchpad.net/bugs/1620323

Title:
  Address Bar Spoofing in Default Browser of Ubuntu LTS.

Status in webbrowser-app package in Ubuntu:
  Confirmed

Bug description:
  Hello ,

  The default browser of the Ubuntu LTS  is vulnerable to Address Bar
  Spoofing.

  Steps :
  Ubuntu browser allows attacker to spoof the web-browser by just using '@' 
symbol.
  Example : https://[email protected] , this will redirect a user or a victim 
to bing.com rather than google.com.
  An attacker can take an advantage of it and may redirect it to any malicious 
website.
  Example : https://[email protected] , similarly this will also 
redirect to attacker.com rather than facebook.com.

  There are various scenario to exploit , one of it using BeeF using [hook.js] 
which is browser based exploitation and as such many more.
  Example: https://[email protected]/hook.js
  Well where as hook.js is a component of BeeF, which allows attacker to  leads 
to browser based exploitation

  As far i recommend and request there should be a pop-up for this as a
  mitigation that some one is trying to tamper the URL.

  Kindly have a look on the attached Video POC , to clear the above scenario.
  I would be happy to hear from the team.
  Thank you

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/webbrowser-app/+bug/1620323/+subscriptions

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to