Closed Bug 1360485 Opened 7 years ago Closed 7 years ago

Firefox is vulnerable to phishing stored in data URI

Categories

(Core :: DOM: Security, defect)

55 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 1331351

People

(Reporter: jm.acuna73, Unassigned)

Details

User Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.81 Safari/537.36

Steps to reproduce:

1- go to http://createcharts.esy.es/data-url.html
2- click button


Actual results:

Phishing stored in data URI


Expected results:

data: URLs are generally a source of confusion for users. Because of their unfamiliarity and ability to encode arbitrary untrusted content in a URL, they are widely being used in spoofing and phishing attacks. Another problem is that they can be passed along without a backing page that runs JavaScript (e.g. a data URL can be sent via email). For that reason, Chrome, IE and Edge block top-frame navigations to data URLs.

I do not understand why it does not Firefox.
Component: Untriaged → Networking
Product: Firefox → Core
I think this more ties into the decision about whether to allow top-level window data: URLs.  I believe Christoph is looking at that.
Component: Networking → DOM: Security
Actually, I think this is just a duplicate of bug 1331351.  We are currently waiting on telemetry data to come back before we make the decision.
Status: UNCONFIRMED → RESOLVED
Closed: 7 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.