Closed
Bug 1363084
Opened 9 years ago
Closed 9 years ago
Fishing with img Tags
Categories
(Firefox :: Untriaged, defect)
Firefox
Untriaged
Tracking
()
RESOLVED
DUPLICATE
of bug 1357835
People
(Reporter: blog, Unassigned)
Details
Attachments
(1 file)
|
20.61 KB,
image/jpeg
|
Details |
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.96 Safari/537.36
Steps to reproduce:
creat a html file and input <img src="http://404.so/base.php" >
Actual results:
open the file with firebox
You will see a pop-up box to enter user name and password
Expected results:
IMG tag Load Fail
This feature can be used as a phishing agent (The hacker can use tempting domain replace the 404.so)
Comment 3•9 years ago
|
||
This is an old issue (bug 647010) that broke large parts of the web when we tried to "fix" it (bug 1197944). We are trying a more limited fix along the lines of what Chrome is doing in bug 1357835
Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•