Closed
Bug 1576623
Opened 6 years ago
Closed 6 years ago
"Report Deceptive Site" can be blocked via onbeforeunload
Categories
(Firefox :: Security, defect)
Firefox
Security
Tracking
()
RESOLVED
DUPLICATE
of bug 1263100
People
(Reporter: emz, Unassigned)
Details
Attachments
(1 file)
1.03 KB,
text/html
|
Details |
A website can call window.location.reload()
in an beforeunload
event handler to block users from reporting it to SafeBrowsing via the Firefox UI (Help -> Report Deceptive Site).
Instead of navigating to the SafeBrowsing report page, the browser will perform a reload of the current page.
I've attached a PoC.
Found on this scam website: hxxp://prize6127.tutonhamon71.live/6426073502/?u=gg4p605&o=5ffwrnh&f=1
Reporter | ||
Updated•6 years ago
|
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → DUPLICATE
Updated•1 year ago
|
Group: firefox-core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•