The PhishingAlert of Safari stops functioning in Windows systems if an abnormal URL is being used.
79d05414fca80bf21d6c2eb1c842e21bb4fd3ab573ff1e90f90b60fa32541ebb
*Abstract:*
The PhishingAlert of Safari stops functioning in Windows systems if an
abnormal URL is being used.
*Details:*
There is a defense mechanism in Safari which recognizes URL deceits such as
https://www.baidu.com@evil.com. The phishing alert will be activated once
the HTTP URL that we want to access contains userinfo information.
(as the picture below shows)
[image: ÄÚǶͼƬ 1]
> https://apple.com@xsser.me/
*Proofs of concept:*
We discovered in our researches that if one or two ¡°/¡± are being added
before the host name, then the PhishingAlert could be bypassed. (Password
of userinfo must be available)
[image: ÄÚǶͼƬ 2]
https://apple.com:£¯@/xsser.me/
*From:*https://en.wooyun.org/bugs/wooyun-2013-014
--
WooYun, an Open and Free Vulnerability Reporting Platform
For more information, please visit *https://en.wooyun.org/about.php
<https://en.wooyun.org/about.php?>*