Browser Navigation Download Trick



EKU-ID: 2218 CVE: OSVDB-ID:
Author: lcamtuf.coredump.cx Published: 2012-05-31 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Another moderately interesting tidbit, I guess...

It is an important and little-known property of web browsers that one
document can always navigate other, non-same-origin windows to
arbitrary URLs. Perhaps more interestingly, you can also navigate
third-party documents to resources served with Content-Disposition:
attachment, in which case, you get the original contents of the
address bar, plus a rogue download prompt attached to an unsuspecting
page that never wanted you to download that file.

PoC:
http://lcamtuf.coredump.cx/fldl/

==========


==========


More info:
http://lcamtuf.blogspot.com/2012/05/yes-you-can-have-fun-with-downloads.html

It's closely related to many other fundamental, open issues with
browser UI design - but I guess it's an interesting highlight.

/mz