4 ms·
Neat, but don't think its exploitable in reality, but neat indeed. Did a bit of play around with it and it does seem to work on input fields but fortunately no
by lepunk 11y ago
Neat, but don't think its exploitable in reality, but neat indeed.
Did a bit of play around with it and it does seem to work on input fields but fortunately not on password type fields (which is logical, considering the browser is not rendering the actual characters for password fields)
http://lepunk.co.uk/font_face.html http://lepunk.co.uk/font_face.html
- blowski 11y ago> considering the browser is not rendering the actual characters for password fields Unless you've got a 'show password' checkbox (as recommended by Jakob Nielsen - http://www.nngroup.com/articles/stop-password-masking/ http://www.nngroup.com/articles/stop-password-masking/).
- seszett 11y agoI know of one community website that allows users to use custom third-party CSS and that shows a user's email address in the settings page, so I think you could at least leak email addresses through this (you can target a single input with the fake font, and email addresses aren't random, so the caveat of repeated characters not showing isn't that problematic). This site doesn't allow password unmasking, but if it did that would also make it quite vulnerable on this front.
- gorhill 11y agoI can't make this work on my side, both Chromium and Firefox block the requests for the font resources from l0.cm (because CORS policy): Font from origin 'http://l0.cm' has been blocked from loading by Cross-Origin Resource Sharing policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'http://lepunk.co.uk' is therefore not allowed access.
- lepunk 11y agoi think thats just a matter of adding this header on the server side Access-Control-Allow-Origin:
- Buge 11y agoThat warning just stops the font from being visible to the victim. I'm pretty sure the requests still go to the attacker.
- gorhill 11y ago> I'm pretty sure the requests still go to the attacker You are right, they do, it's just that the returned data is not allowed to be seen/used by the page -- the "l0.cm" server still got the information.
- malka 11y agoExcept for Edge, which has an "eye" symbol to show password fields content. idk if that makes edge vulnerable to this on password fields though. edit : I read below that Edge does not expose the password through this vulnerability.