SOP bypass / UXSS – Stealing Credentials Pretty Fast (Edge)

A brokenbrowser.com mögött álló argentin biztonsági szakértő, Manuel Caballero egy újabb szórakoztató Microsoft Edge hiba kihasználását tette közzé:

Today we are going to steal Twitter and Facebook credentials from the user. We did this a few weeks ago, but Charles -our fictional user- has updated Microsoft Edge and changed his password, so he thinks he’s safe now. Charles does not know that the previous two SOP bypasses [1] [2] were not patched and this new one is easier and faster!

[...]

The vulnerability that follows describes how to steal the credentials and cookies from people using Microsoft Edge, and, if they are using the default password manager we will be able to steal them in plain-text pretty fast.

Hozzászólások

nem latom, miert kene valakinek IExplodert vagy annak szarmazekat hasznalnia...

Egy biztonsagi hiba mitol lesz szorakoztato?