Closed Bug 903898 Opened 12 years ago Closed 12 years ago

Possible location bar spoofing when you past a link and go to it

Categories

(Core :: General, defect)

22 Branch
x86_64
Windows 7
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 893312

People

(Reporter: jordi.chancel, Unassigned)

Details

(Whiteboard: [dupeme?])

Attachments

(2 files)

Attached file testcase.html
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:23.0) Gecko/20100101 Firefox/23.0 (Beta/Release) Build ID: 20130729175331 Steps to reproduce: when you copy a link and past and go to it on the location bar, the last content of the link is totaly visible(see screenshot). Actual results: location bar is spoofed. Expected results: last content of the link is totaly visible.
Attachment #788739 - Attachment mime type: text/plain → text/html
Attached file Windows Exemple
I'm confused, you have a link that has google.com in it (from the html you supplied), you copy the link via "copy link location" and then paste that into the url bar, which copies the url from the supplied link. So it pasted exactly what it copied. I'm confused on where the actual vulnerability is here or how this constitutes spoofing?
Flags: needinfo?(jordi.chancel)
this is probably a dupe of bugs that were filed when the design choice was made to show the end of the url, not the front of it. the tab info shows the site info and is expected to steer users away from rouge sites. also you couldn't use this kind of attack when clicking on a link since hovering over a link would reviled the unintended location information. Jordi, can you think of a way that you might be able to trick a user into clicking or copying a link from a remote site and not a link hosted on you local computer like the example you show?
yes execute the testcase in http and it works too ! :)
Flags: needinfo?(jordi.chancel)
based on Comment 3 setting dupeme? in whiteboard, so we can search to see if it is or is not dupe.
Whiteboard: [dupeme?]
Group: core-security
Status: UNCONFIRMED → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Keywords: csec-spoof, sec-low
Please do not sec rate your own bugs
Keywords: csec-spoof, sec-low
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: