E-mail senden E-Mail Adresse kopieren
2014-06-04

Protecting users against XSS-based password manager abuse

Zusammenfassung

To ease the burden of repeated password authentication on multiple sites, modern Web browsers provide password managers, which offer to automatically complete password fields on Web pages, after the password has been stored once. Unfortunately, these managers operate by simply inserting the clear-text password into the document's DOM, where it is accessible by JavaScript. Thus, a successful Cross-site Scripting attack can be leveraged by the attacker to read and leak password data which has been provided by the password manager. In this paper, we assess this potential threat through a thorough survey of the current password manager generation and observable characteristics of password fields in popular Web sites. Furthermore, we propose an alternative password manager design, which robustly prevents the identified attacks, while maintaining compatibility with the established functionality of the existing approaches.

Konferenzbeitrag

ACM ASIA Conference on Computer and Communications Security (AsiaCCS)

Veröffentlichungsdatum

2014-06-04

Letztes Änderungsdatum

2026-06-11