6 ms·
Cursory hack – Fake address bar interaction
- smidgen2 10y agoWhoa that is a sweet hack. You should have submitted it to Google for a bug bounty. It should NOT be possible to clickjack the browser's address bar.
- hexadec0079 10y agoIt isn't though. This merely changes the display of the cursor. Go to windowed mode (not fullscreen) and pull the cursor down into the address bar and tabs area to see that this does not prevent access to the address bar. It only changes how you perceive the position of the cursor.
- wazoox 10y agoOn both Firefox and Chromium on Linux the true place of the real cursor stay visible (Firefox displays a thin cross, and chromium a light blue star). The menu position of course doesn't make sense in Firefox :)
- heywire 10y agoNote: If you have the home button always visible in chrome, or the bookmarks bar hidden, you'll notice that the demo doesn't work properly.
- andybak 10y agoUnless I'm completely getting myself confused then it's doing something I didn't think was possible and drawing over the browser chrome. Can anyone explain what's going on here.
- edvinbesic 10y agoCurious about this as well, didn't think you could escape the viewport but clearly it was overlaying the lock icon in my address bar. The tracking wasn't great, but maybe that was intentional to illustrate a point.
- gabemart 10y agoAfter a first look, it seems like this hack involves setting a custom cursor, which is defined as a canvas image that is 128 px tall. This 128px high image is mostly transparent, and has a fake "cursor" image at the top of it. The bottom of this image tracks your real cursor, and the fake cursor at the top of the image makes it seem like your real cursor is hovering over the browser chrome, when in fact it is ~128px lower than it appears. The rest of the effect is achieved via animating the canvas used for the custom cursor. In terms of mitigation, it seems like at a minimum custom cursors should never be rendered outside the bounds of the page content.
- pingec 10y agoThanks for the explanation. Most informative comment.
- jamesfisher 10y agoHello! Author here (along with my inspiration benjaminbenben). This explanation is perfect. And yes, I think the TODO is to not render the custom cursor outside the viewport.
- Mithaldu 10y agoAre you sure that is possible? At least on Windows, i'm reasonably sure all the API does is tell the OS which image to render as cursor and the cursor is rendered entirely by the OS; meaning there's no control over whether the cursor is being rendered partially outside the viewport or not. Solutions where the browser would have enough control would likely require rendering the cursor by itself, which would impart it noticable input latency. Edit: Quick addition of a bounding box to the demo: https://wchristian.github.io/cursory-hack/ https://wchristian.github.io/cursory-hack/
- jabiko 10y agoThe browser could check whether the cursor image would be painted outside the page viewport. In this case the browser could create a clipped version of the cursor image and set it as the new cursor.
- CatsoCatsoCatso 10y agoOn Chrome Windows 7 version I've got the window un-maximised and the pretend cursor escapes well onto the desktop and outside the bounds of the visible Chrome window itself.
- vollmond 10y agoDitto on Win10
- Raphmedia 10y agoMove the cursor farther up and you will see it jump.
- fovc 10y agoLink to the source on github for anyone else without a view source button: https://github.com/jameshfisher/cursory-hack/blob/gh-pages/index.html https://github.com/jameshfisher/cursory-hack/blob/gh-pages/i... It's using a canvas to draw the address bar and adjusting the position every time the mouse moves, but I don't understand the details of it
- deleted 10y ago[deleted]
- oolongCat 10y agoBefore you click on that remember. Alt + Left to go back :P
- redbeard0x0a 10y agoFor those on mac: ⌘ + Left (go back) ⌘ + W (closes the window)
- rShergold 10y agoCredit where it's due. It seems this is illustrating a sinister use of the original code found here: https://github.com/benfoxall/cursory-hack https://github.com/benfoxall/cursory-hack
- dividuum 10y agoDemo: https://rawgit.com/benfoxall/cursory-hack/gh-pages/ https://rawgit.com/benfoxall/cursory-hack/gh-pages/
- jamesfisher 10y agoHa, yes, Ben himself posted this to HN - I didn't realize it was going public!
- athenot 10y agoDoesn't seem to work in Safari.
- mrweasel 10y agoOr Firefox
- benwaffle 10y agoor on HiDPI
- hexadec0079 10y agoOr on Netscape Navigator
- HeadlessChild 10y agoOr in lynx
- strictnein 10y agoConfirmed in cURL
- yladiz 10y agoSo I thought this was just doing something on click (showing the fake HTTPS info), but that it maybe didn't work on newer or non-Chrome browsers, e.g. Chrome 52, Safari 9.1, and whatever bug was fixed there. But then I noticed that it causes really weird interactions at the top of the browser, at least on Mac; if you open the page in either Chrome or Safari and move your mouse towards the address bar, it jumps around on Safari and does a "double take" on Chrome. Really interesting!
- sp332 10y agoI'm using Firefox on Windows and it's awfully flickery but it does work.
- ikeboy 10y agoSomeone should combine this with a "change the address bar url without reloading" in javascript to make it complete. Edit: looks like it only works on the same origin.
- angry-hacker 10y agoThere are several similar reports on chromium project. All of them are nofix.
- Herrera 10y agoReally? That is strange, because there is ways this could be exploited... Can you link them to me?
- angry-hacker 10y agohttps://news.ycombinator.com/item?id=12260444 https://news.ycombinator.com/item?id=12260444 Sorry, I'm on mobile. But several similar reports as the HN link shows.
- benten10 10y agoInteresting... Can this 'hack' be used to convince people that, say, they're in a different/secure website when they're in a malicious website? I ask because since the 'fake' cursor is visible even on the address bar, the page must be able to overwrite the pixels there?
- joshstrange 10y agoAs this demo is now (and probably even with a lot of work) no due to the vast number of browser chrome (UI, not google chrome) configs. It's also very jittery in the demo. That said there is plenty of room for abuse in clicking things like like/tweet/etc buttons it would appear.
- amga_ 10y agoSource code: https://github.com/jameshfisher/cursory-hack https://github.com/jameshfisher/cursory-hack
- yumaikas 10y agoEven if that's not able to directly take over the web browser, it's really annoying to have your mouse taken over like that.
- milankragujevic 10y agoOn Safari on OS X 10.11 it just blinks the page.
- eridius 10y agoThe original linked hack is clever. But this page is just confusing (in Safari on OS X), for several reasons, not the least of which is the fact that the page is in fact served over https, and if I mouse over the padlock and click it, everything behaves correctly (and even if the page was specially designed for Safari and could figure out where the url bar was, it can't even replicate the behavior Safari has for clicking the padlock because web pages can't show sheet dialogs). Part of the problem here is the fact that the fake cursor never actually escapes the page on this one. When my mouse is near the top of the page it reverts back to the system cursor instead of the fake one, before it even leaves the frame of the page. The original linked hack worked much better.
- wodenokoto 10y agoin firefox, you can't