首页> 外文会议>IEEE Symposium on Security and Privacy >All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API
【24h】

All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API

机译:您所有的屏幕都属于我们:利用HTML5屏幕共享API的攻击

获取原文

摘要

HTML5 changes many aspects in the browser world by introducing numerous new concepts, in particular, the new HTML5 screen sharing API impacts the security implications of browsers tremendously. One of the core assumptions on which browser security is built is that there is no cross-origin feedback loop from the client to the server. However, the screen sharing API allows creating a cross-origin feedback loop. Consequently, websites will potentially be able to see all visible content from the user's screen, irrespective of its origin. This cross-origin feedback loop, when combined with human vision limitations, can introduce new vulnerabilities. An attacker can capture sensitive information from victim's screen using the new API without the consensus of the victim. We investigate the security implications of the screen sharing API and discuss how existing defenses against traditional web attacks fail during screen sharing. We show that several attacks are possible with the help of the screen sharing API: cross-site request forgery, history sniffing, and information stealing. We discuss how popular websites such as Amazon and Wells Fargo can be attacked using this API and demonstrate the consequences of the attacks such as economic losses, compromised account and information disclosure. The objective of this paper is to present the attacks using the screen sharing API, analyze the fundamental cause and motivate potential defenses to design a more secure screen sharing API.
机译:HTML5通过引入许多新概念改变了浏览器领域的许多方面,特别是新的HTML5屏幕共享API极大地影响了浏览器的安全性。建立浏览器安全性的核心假设之一是,没有从客户端到服务器的跨域反馈循环。但是,屏幕共享API允许创建跨域反馈循环。因此,无论潜在来源如何,网站都将有可能从用户的屏幕上看到所有可见内容。当跨源反馈循环与人类视觉限制结合在一起时,可能会引入新的漏洞。攻击者可以使用新的API从受害者的屏幕上捕获敏感信息,而无需受害者的共识。我们研究了屏幕共享API的安全隐患,并讨论了在屏幕共享过程中针对传统Web攻击的现有防御措施是如何失败的。我们展示了使用屏幕共享API可以进行多种攻击:跨站点请求伪造,历史嗅探和信息窃取。我们讨论了如何使用此API攻击诸如Amazon和Wells Fargo之类的流行网站,并论证了这些攻击的后果,例如经济损失,帐户被盗和信息泄露。本文的目的是介绍使用屏幕共享API的攻击,分析根本原因并激发潜在的防御措施,以设计更安全的屏幕共享API。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号