Do not allow an auth prompt requested by an image resource loaded from cross-origin

RESOLVED FIXED in Firefox 59

Status

()

P3
normal
RESOLVED FIXED
a year ago
8 months ago

People

(Reporter: dragana, Assigned: dragana)

Tracking

({dev-doc-complete, site-compat})

59 Branch
mozilla59
dev-doc-complete, site-compat
Points:
---

Firefox Tracking Flags

(firefox59 fixed)

Details

(Whiteboard: [necko-triaged])

Attachments

(1 attachment)

(Assignee)

Description

a year ago
We only need to change  pref.
(Assignee)

Comment 1

a year ago
Chrome already have this as default(bug 647010 comment 87) so I do not expect that we will break something.
(Assignee)

Comment 2

a year ago
Created attachment 8934471 [details] [diff] [review]
bug_1423146.patch
Attachment #8934471 - Flags: review?(ckerschb)
Do we need an intent-to-ship for this?
Depends on: 1357835
Attachment #8934471 - Flags: review?(ckerschb) → review+
(Assignee)

Comment 5

a year ago
(In reply to Christoph Kerschbaumer [:ckerschb] from comment #4)
> Do we need an intent-to-ship for this?

I will write one, although Chrome already implement this.
Keywords: dev-doc-needed, site-compat
Priority: -- → P3
Whiteboard: [necko-triaged]

Comment 6

a year ago
Pushed by dd.mozilla@gmail.com:
https://hg.mozilla.org/integration/mozilla-inbound/rev/1a59ea77d44f
Change a pref so that an auth prompt requested by an image resource loaded from cross-originis not allowed. r=ckerschb

Comment 8

a year ago
bugherder
https://hg.mozilla.org/mozilla-central/rev/1a59ea77d44f
Status: ASSIGNED → RESOLVED
Last Resolved: a year ago
status-firefox59: affected → fixed
Resolution: --- → FIXED
Target Milestone: --- → mozilla59
I've documented this on MDN:

* Added a note to the Fx59 rel notes:
https://developer.mozilla.org/en-US/Firefox/Releases/59#Security

* Added a small section to the HTTP authentication page:
https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication#Authentication_of_cross-origin_images

Let me know if this is OK. Thanks!
Flags: needinfo?(dd.mozilla)
Keywords: dev-doc-needed → dev-doc-complete
(Assignee)

Comment 10

11 months ago
(In reply to Chris Mills (Mozilla, MDN editor) [:cmills] from comment #9)
> I've documented this on MDN:
> 
> * Added a note to the Fx59 rel notes:
> https://developer.mozilla.org/en-US/Firefox/Releases/59#Security
> 
> * Added a small section to the HTTP authentication page:
> https://developer.mozilla.org/en-US/docs/Web/HTTP/
> Authentication#Authentication_of_cross-origin_images
> 
> Let me know if this is OK. Thanks!

Looks good. Thanks.
Flags: needinfo?(dd.mozilla)

Comment 11

8 months ago
Hello!

This bug is just the same as my Bug 647010, which I informed Mozilla about in March 2011. This is vulnerability in all browsers, which support Basic/Digest Authentication, as I wrote in my entry. So a lot of web browsers are vulnerable, not only Firefox.

I called this attack as Onsite phishing (or Inline phishing). It can be used (including by phishers) for stealing of logins and passwords of users of web sites.
You need to log in before you can comment on or make changes to this bug.