Rootkits for JavaScript environments

  • Authors:
  • Ben Adida;Adam Barth;Collin Jackson

  • Affiliations:
  • Harvard University;UC Berkeley;Stanford University

  • Venue:
  • WOOT'09 Proceedings of the 3rd USENIX conference on Offensive technologies
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

A number of commercial cloud-based password managers use bookmarklets to automatically populate and submit login forms. Unfortunately, an attacker web site can maliciously alter the JavaScript environment and, when the login bookmarklet is invoked, steal the user's passwords. We describe general attack techniques for altering a bookmarklet's JavaScript environment and apply them to extracting passwords from six commercial password managers. Our proposed solution has been adopted by several of the commercial vendors.