No account yet?
Home ยป Downloads
Document Details
 

Stealing Passwords Via Browser Refresh





Description: Browsers have the ability to maintain a recent record of pages that were visited by a user. The back and forward button on browsers use this functionality to display the pages recently browsed. In addition browsers also keep track of variables that were POSTed to the server while fetching the page. The refresh feature immensely increases the functionality of the browsers and makes it convenient for users. Moreover it is done transparently so that users do not need to be aware that the variables are automatically posted to the server. All that a user has to do is to click on the “yes” button of a dialog box prompted by the browser before re-posting. This lets a user view the same pages that he had visited before. Considering functionality, this is a very powerful feature but it can also be used to capture important user credentials from a browser. Here the inherent feature of the browser to store POST variables is exploited to gain access to important user credentials. We will also be discussing another variation of the attack. These attacks are very simple to execute and require medium level of skills. For each variation of the attack we have proposed the solution used to address the issue.
Property Value
Name Stealing Passwords Via Browser Refresh
Keywords
Filesize Empty
Google Ads
Filetype pdf (Mime Type: application/pdf)
Creator Everybody
Created On: 08/05/2005 00:00
Viewers Everybody
Maintained by Zinho
Hits 0 Hits
Last updated on 12/31/1969 16:00
Homepage
CRC Checksum
MD5 Checksum


You need to login to download texts/tools. Register here, it's fast and free!

Downloads Home
Downloads Home
Search Document
Search Document

Get Archive RSS

The latest tools and texts wherever you are


Do you own a website?
Add these feeds to your site and get a link on our home page!

Newsletter


Every week our tools in your inbox?


Enter your Email


Preview

Security Services by HSC