Nytro Posted March 5, 2013 Report Posted March 5, 2013 Rootkits for JavaScript EnvironmentsBen AdidaHarvard Universitybenadida@harvard.eduAdam BarthUC Berkeleyabarth@eecs.berkeley.eduCollin JacksonStanford Universitycollinj@cs.stanford.eduAbstractA number of commercial cloud-based passwordmanagers use bookmarklets to automatically populateand submit login forms. Unfortunately, an attacker website can maliciously alter the JavaScript environmentand, when the login bookmarklet is invoked, steal theuser’s passwords. We describe general attack tech-niques for altering a bookmarklet’s JavaScript envi-ronment and apply them to extracting passwords fromsix commercial password managers. Our proposedsolution has been adopted by several of the commercialvendors.Download:http://static.usenix.org/event/woot09/tech/full_papers/adida.pdf Quote