Apple Safari on MacOSX may reveal user's saved passwords

看板Bugtraq作者時間18年前 (2007/05/15 03:49), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/11 (看更多)
hello, Apple Safari on Macosx may reveal user's saved passwords. A local user with legitimate access to the system is able to steal keychained password by injecting javascripts into a loaded webpage via applescript. It seems that safari fails to validate the source of injected code, however apple belives this is the correct behaviour so no fixes will be made available. this proof of concept scpt file will display the password loaded by safari into an html object named "password": tell application "Safari" do JavaScript "alert(document.loginform.password.value)" in document 1 end tell comments are welcome cheers, -poplix http://px.dynalias.org
文章代碼(AID): #16IBra00 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 1 之 11 篇):
文章代碼(AID): #16IBra00 (Bugtraq)