12 ms·
Browser auto-fill phishing
- danso 10y agoWow, this seems like such an obvious attack vector that I just assumed it was somehow mitigated (somewhere, magically, I suppose). Does it even require the user to press the Submit button, i.e. could the site's JS trigger the POST request after the event of the autofill?
- alexwebb2 10y agoNo need for a submit click. Presumably auto-fill triggers a change event on each affected input, but even if it didn't, an attacker could just repeatedly check for new content in the inputs. This means an optimistic solution (autofilling and then unobtrusively notifying the user what was autofilled) is not viable.
- tiglionabbit 10y agoNotice that it's not checking the data with JavaScript. I was under the impression that there is already a security measure against this as far as JavaScript is concerned. The browser is already instructed to lie to JavaScript about certain details such as the :visited state of a link and any CSS rules that follow as a result of this.
- greenhatman 10y agoEven if you can't read the values with JavaScript, you can submit the form with JavaScript. So then you'd need to prompt the users to confirm that they want to auto fill, not just notify that auto fill happened. Otherwise it may already be too late.
- nommm-nommm 10y agoEven if you couldn't read any hidden value with JS and had no way of telling if they changed (didn't try it myself) you could submit the form every 5-10 seconds or so in the background and reject it server side if a hidden field is missing.
- tyingq 10y agoYou can check the data with JavaScript if you poll. Try it out: https://jsfiddle.net/k91o1dw9/7/ https://jsfiddle.net/k91o1dw9/7/
- bsimpson 10y agoI don't think it does trigger a change for exactly this reason. I tried to build a Material login page a couple years back, where the placeholder became the label when you typed. I couldn't get it to work with autofill, because I couldn't find a vector to detect when autofill had happened. Here's a related issue: https://bugs.chromium.org/p/chromium/issues/detail?id=352527 https://bugs.chromium.org/p/chromium/issues/detail?id=352527
- deleted 10y ago[deleted]
- mbrookes 10y agoThat's correct - this has also been a massive issue for React, and still isn't fixed in a released version. There's a fix that was merged some time ago, pending release with React 16 [1]. There's some discussion about a 3rd party effort to back-port to 15.x. [1] https://github.com/facebook/react/issues/7211#issuecomment-266774957 https://github.com/facebook/react/issues/7211#issuecomment-2...)
- tyingq 10y agoIt doesn't trigger a change, but you can certainly poll for non empty strings: https://jsfiddle.net/k91o1dw9/7/ https://jsfiddle.net/k91o1dw9/7/ Edit: That is, for the purposes of this exploit. I understand it's ugly.
- dyim 10y agoYup, you could AJAX-ily listen to the phish fields
- deleted 10y ago[deleted]
- joshmn 10y agoGenius.
- aesthetics1 10y agoWow, great demonstration. I'd never thought about this being exploited. I wonder if the fix could be something as simple as the browser only allowing non-hidden [Edit: "not visible to the user", I should have said, as this does not appear to auto-fill <input type="hidden"> ] fields to be auto-filled. Otherwise, a warning about what auto-fill information (IE "Your name and credit card information are going to be submitted, continue?") has been filled in would be a nice touch. Maybe a browser extension could accomplish this?
- alexwebb2 10y agoOnly allowing non-(display:none) fields wouldn't be enough. You could still position them off screen, or behind an image, or very small or nearly transparent, or any other sneaky tactic. Your second idea about an auto-fill warning would be better. Maybe a simple footer warning or something.
- aesthetics1 10y agoI guess I did not think about offscreen or otherwise sneakily positioned form elements. I think the warning is the best way to handle this. I imagine it being something similar to an android permissions popup, where you can check off what should be "shared" (auto-filled) with the site before actually populating the form.
- jerf 10y agoThen you'll love this concept: https://www.youtube.com/watch?v=3mk0RySeNsU https://www.youtube.com/watch?v=3mk0RySeNsU A 1:18 "clickjacking" demo. (Link to video because I think this is legitimately one of those cases where a video can describe and demonstrate the problem faster than text.) You can google around for more info, or at least my YouTube is definitely popping up some other relevant videos.
- bobbles 10y agoSomething like "Chrome has autofilled 12 fields" or something more userworldy would be good. Or massive highlighting around each field
- thesumofall 10y agoEven as an experienced user it never crossed my mind that this might happen. Good catch
- FryHigh 10y agoThis vulnerability was published (another article) over a year ago. I'm surprised Chrome hasn't fixed it. I think this means browsers will never fix this issue. I won't be using auto-fill on untrusted webaites.
- robert_tweed 10y agoThis is a very old exploit. The earliest references I could find were from 2010. As other comments have noted, it isn't trivial to fix completely, so I believe most browsers just haven't bothered at all, but have implemented some extra protection for credit cards (and of course, CVV numbers are never stored in the first place).
- amenod 10y agoNot all browsers - Firefox suggests form input values one by one (when you click in the field) so it is not vulnerable AFAICT.
- daheza 10y agoI found this https://bugs.chromium.org/p/chromium/issues/detail?id=132135 https://bugs.chromium.org/p/chromium/issues/detail?id=132135 which was created when someone noticed the issue happening to their honeypot input box. Looks like it was closed a while ago. I saw this example doing the rounds on twitter. Hopefully the chrome devs notice the noise and move up the priority on fixing / addressing it.
- Terr_ 10y ago> Chrome Autofill is specifically designed to help users quickly fill forms that they've never filled before. Browsers auto-guessing private data into arbitrary fields on never-before-used webpages? IMO that's "Just because you can doesn't mean you should" territory.
- error54 10y agoIn case anyone is worried, most (all?) browsers do not autofill credit card information without the user explicitly clicking into the credit card field so there's no chance of a hidden field stealing your CC information.
- flanbiscuit 10y agoAnd even when clicking into the credit card field you still need to click a little popup that asks if you want to autofill.... at least that's how it works for me, I don't remember ever changing a setting on Chrome for this so I assume this is the default state. In fact it does something similar for my address information too. There must be some setting because I know my address autofill info is saved in Chrome but when I tried the demo I did not see my address info in the headers
- lightbyte 10y agoLast time I autofilled a CC with chrome it asked me to input the cvv number on the card before it filled in.
- gohrt 10y agoInteresting use of CVV, since vendors aren't permitted to store it. But Chrome does, for you... is that synced across browsers? That would require Google to store the CVV on its servers...
- bradjohnson 10y agoI don't know about this feature, but why couldn't it be stored as a hash?
- Scirra_Tom 10y agoI might be an order of magnitude off here, but I believe there's only around 1 billion unique numbers per card once you take away check sum digits and look at how they are issued. Assuming that's correct, it really wouldn't take up much memory or computing power to create a lookup table for every credit card number with hash x.
- robertelder 10y agoI really with that browsers didn't autocomplete ever. I've had instances where they will happily auto-complete my entire credit card number. Usually, they'll only memorize the first 4 digits, but sometimes they memorize the entire thing.
- kardos 10y agoYou can disable it, https://support.mozilla.org/en-US/kb/control-whether-firefox-automatically-fills-forms#w_prevent-firefox-from-storing-form-entries https://support.mozilla.org/en-US/kb/control-whether-firefox... https://support.google.com/chrome/answer/142893?co=GENIE.Platform%3DDesktop&hl=en https://support.google.com/chrome/answer/142893?co=GENIE.Pla...
- avh02 10y agoautofill actually annoys me, which is why it's one of the first things i disable when setting up my browser(s)
- flanbiscuit 10y agoFor me it pops up a little box under the input asking me to choose if I want to autofill. I like this option because it doesn't autofill without permission but my info is still saved and easily accessible.
- thebosz 10y agoFirefox doesn't exhibit this behavior, but the site doesn't specifically state which browsers this affects.
- vog 10y agoIndeed, I'm really glad there is at least one popular browser not affected by this. This is one of the many examples where a privacy-first approach pays off not just in terms of privacy but also in terms of security. In Germany we use the term "Datensparsamkeit" for this principle. Not sure if there is a well-established english term in the international community. So why do other browers fill in these fields automatically? Why don't they wait until asked by the user? Because it is more "convenient" for the user? Moreover who benefits from that? Not the users, not the browser vendors, but all those websites with overly long registration forms. These confront their visitors with lots of irrelevant fields (birthday, gender, etc.) just for the sake of collecting data. Nobody would fill all that in voluntarily, but I guess more people will do so (perhaps accidentally) if their browser fills that in by default.
- hashhar 10y agoFirefox is secure against this. FF needs you to right click an input field and select an identity to use for autofill. But Safari does it in the most elegant way. They show a popup with all the information that will be autofilled and ask you to confirm before filling out the fields which also protects against AJAXified submissions.
- ericrav 10y agoI'd rather have only the field I selected autofilled and be given a secondary option to have every field (or maybe choose which fields) in a form autofilled. This bothers me in innocent, non-phishing forms too—especially when the designers don't put labels on the fields and only use placeholders, which I can no longer see after autofill.
- kalleboo 10y agoSafari lets you choose which fields to fill in by clicking a "Customize" option that pops up, but I doubt any normal user will bother looking that far.
- matt_wulfeck 10y agoThe only thing I can think of is a separate prompt, that would ask "Do you want to autofill Name, Address, Phone..." etc.
- Sephiroth87 10y agoThat's what Safari actually does
- vog 10y agoThat popup is not needed. Firefox does this simply through auto-complete. The user starts typing their email address, and voila, the browser completes it. This is a nice example of a feature that is trivially accessible and yet unobtrusive. (Alternatively, you can press the down-arrow on the empty field, which will open the auto-completion as well.)
- takeda 10y agoOld Opera went one step further, where it would fill forms using a Wand button. This approach also was used for logging in. IMO, much better way, since it works well in situation where your passwords are encrypted and browser is configured to forget master key after a while. Firefox in that scenario will bug you about master password each time you go to page where such password is stored.
- shefaliprateek 10y agoare there are api products or chrome-plugins to check / verify if a certain page is a phishing-attack ?
- stabbles 10y agoI wrote about this a while ago: https://medium.com/@stabbles/why-you-should-disable-autofill-bf2e15c65b5c https://medium.com/@stabbles/why-you-should-disable-autofill...
- danielweber 10y agoAnd Jeremiah Grossman was talking about it a decade ago. It's amazing these problems persist.
- ssttoo 10y agohaha, I guess I also reinvented the wheel a few months later :) http://www.phpied.com/oversharing-with-the-browsers-autofill/ http://www.phpied.com/oversharing-with-the-browsers-autofill...
- bored 10y agoAlso, malicious scripts can change the password input type field to a regular text field and grab it from there.
- talmand 10y agoThere's no need to convert the input type to get the plain text value of a password input. It just masks the input value visually.
- hajderr 10y agoGreat state of the web
- talmand 10y agoIt's not the web as it's working as it should, this is a browser problem.
- VarunAgw 10y agoIf I remember correctly, it has been reported several times in the past and Chrome doesn't care about it at all.
- alpb 10y agoJust confirmed 1Password’s AutoFill for identity is also vulnerable to this on Chrome.
- zacharycohn 10y agoSaw the title of this, didn't even open the link, just thought "oh... Crap."
- TheRealPomax 10y agoWas this filed against Firefox, Chrome, and EDGE? (it seems like the kind of PoC that you make to prove a point to browser vendors to get them to fix what should obvioulsy be fixed... if the user can't see it, no matter how that's been achieved, don't autofill that field.)
- lucb1e 10y agoFirefox is not vulnerable. Chrome was shown to be vulnerable like 7 years ago but nothing changed. Closed source stuff like MSIE or Safari? No idea, ask a Windows os OS X user.
- TheRealPomax 10y agoMS EDGE, unlike the now hopelessly outdated Internet Explorer, has an open issue tracker. And as Safari is literally just webkit, which also has an open issue tracker, there was no need to pretend to be better than Windows and OSX users by pretending they're on their own.
- nine_k 10y agoThis is why I never put anything secret into browser autofill data. No credit cards, no passwords, nothing I would not be OK with disclosing publicly, or already did. Sensitive info belongs to a password manager which limits it to the domains the data belong. Credit card numbers are a pain, though. I could put them to a password manager, and manually select to fill only that particular field when I need to. In reality I rarely buy things where PayPal or Amazon payment options are not available; I suppose Stripe offers a similar service.
- gohrt 10y agoBrowsers don't auto-fill credit cards and passwords, today, because they are private. Chrome (and I assume others) has a secure credit card and password auto-fill, separate from regular form auto-fill.
- nucleardog 10y ago> Sensitive info belongs to a password manager which limits it to the domains the data belong. So all that stands between you and being in this exact situation (or worse, since passwords) is your password manager's url comparison? I refuse to use LastPass - the interface is horrible (probably because you're expected to use the browser extension). But I don't want my password manager anywhere near my browser. I'd really rather have to take an affirmative action in order to release each individual piece of information so I know what I'm disclosing and to who.
- cbr 10y agoyour password manager's url comparison? Better than manual url comparision! A surprising number of humans think things like www.goodcompany.evil.com are urls for "Good Company", and anyone can screw up and make mistakes checking urls (www.goodcomany.com).
- ksenzee 10y agoAdd Unicode and it gets worse. I don't trust my eyes to differentiate between Cyrillic а and Latin a. https://en.wikipedia.org/wiki/IDN_homograph_attack https://en.wikipedia.org/wiki/IDN_homograph_attack
- misterballs 10y agoFillr autofill app requires users to approve every piece of data before autofilling a form. Makes it easy to know when a site is trying something shifty. Dashlane also lets you pick exactly what to fill. Native browser autofills have been battling phishing exploits since early IE days.
- grandalf 10y agoThis is a very clever hack. I've tried in the past to adjust my HTML to disable autofill and it's not possible to prevent Chrome from aggressively doing it.
- hamhamed 10y agoIt's disabled if you do autocomplete=off in the attributes
- grandalf 10y agoNot in my tests, it continued to aggressively populate forms with autocomplete="off" set.
- talmand 10y agoThat would be because that attribute is for a different feature of the browser. The autofill that this method takes advantage of is more of an extension beyond the standard browser feature. Besides, someone using this for a phishing method wouldn't use that attribute anyway.
- deleted 10y ago[deleted]
- SippinLean 10y agoLastPass prompts every time before autofilling your CC# into a form, so it might avoid this issue in that case. I do believe it would still fail exposing your basic info, such as in this example, however.
- tcoff91 10y agoLastPass has previously had autofill exploits (not with regards to CC though). I would highly recommend disabling auto-fill.
- inopinatus 10y agoBasic info is more critical than credit card numbers, at least in my country (Australia) where the issuer or merchant would be liable for any subsequent fraudulent transactions; at worst I would be inconvenienced a few days whilst a new card & number was issued. Compared to outright identity theft, that's minor.
- throwaway2016a 10y agoComplete tangent but... why is this a NPM package? There is no actual Javascript code in it.
- robert_tweed 10y agoIt's not actually published on npmjs.org. Author probably just ran npm init out of force of habit. It's actually quite nice that they have their standard metadata & licence where it's easy to find. They should probably have private: true in there though, to stop it getting published by mistake, since it isn't a component anyone could usefully import.
- tcfunk 10y agoI actually ran across this a while ago, but didn't think to call it phishing. I was trying to create a honeypot for a front-facing web form, but because of the name I gave the honeypot field, some people's autofill information was filling out that field without them knowing.
- tiglionabbit 10y agoThis could be solved by improving the autofill UI to tell you all the data it is filling into the form, even if it isn't visible to you. Currently, when I trigger autofill in Chrome, it tells me the full suite of information it can input for a certain profile (name, address, company, etc), but it doesn't tell me which bits of information are actually being used. Something as simple as placing checkmarks in this popup next to the information that is actually being used could communicate this better.
- kalleboo 10y ago> This could be solved by improving the autofill UI to tell you all the data it is filling into the form, even if it isn't visible to you. Safari does this already
- shurcooL 10y agoThis is the reason I never use the autofill beyond more than at typechecker. I still explicitly write out what I want to place in the form, and the autofill helps me avoid typos. However, I always found it odd how something so prone to this kind of attack could be deployed for all non-tech savvy browser users...
- noblethrasher 10y agoIt even works in incognito mode (Chrome 55.0.2883.87 on Windows 8.1; tested against my bank's website).
- robinduckett 10y agoDidn't work for me. Chrome 55.0.2883.87
- dexterdear 10y agook lets try..
- dexterdear 10y agook, let's try.
- deleted 10y ago[deleted]
- avodonosov 10y agoAnd Chrome wants to ignore autocomplete=off (https://news.ycombinator.com/item?id=11911116 https://news.ycombinator.com/item?id=11911116)
- ycmbntrthrwaway 10y agoWhy not? Anyone who wants to steal your information would not try to disable autocomplete anyway.
- avodonosov 10y agoYou're right, following standard in regard to autocomplete=off will not prevent this attack. I think I remembered of that because the direction of though that autocomplete should always be enabled appears as wrong to me. And this situation reminded me of this direction of though in the past case.
- joantune 10y agoYes! I always had this itch whenever I filled out a field and had the other fields pre filled by chrome. I actually thought that maybe there were type="hidden" that could have been filled and sent (although as someone points out those aren't but it isn't hard to hide an input with CSS). But the main point is: whenever I did that I was usually OK with sending out the rest of the information which either was outdated or I was consciously aware of it. However, a lot of users might not have that conscience and might be giving out information which they didn't want to. It would be great to shame websites that were employing these shady techniques, but the solution must come from Chrome. Chrome devs: by default only auto fill one field and on the drop down have as the last option to do what you do now, so that you're sure that the user has consciously chosen to auto fill all fields * have a little disclaimer saying this possibility *. That way you get the best of both worlds with an extra key down
- joantune 10y agoPS: and/or like someone said that happens in Safari: name the fields that you are about to autofill in the last choice to autofill everything
- deleted 10y ago[deleted]
- ComodoHacker 10y agoI get 405 after submit.
- jaakl 10y agome too, but just use the developer console to see the same (horrifying) results as shown in the gif.
- ulber 10y agoSave forms data and especially save passwords have always seemed phishy to me.
- kexing 10y agotest
- digi_owl 10y agoYet more blowback from trying to be "user friendly"...