Stealing Passwords via Browser Refresh
The browser’s “Refresh” feature was the source of a little known vulnerability until last year, when Karmendra analyzed the issue in Stealing Passwords via Browser Refresh.
Karmendra showed how applications that did not issue an HTTP redirect during authentication could be persuaded to reveal the previous user’s password, even after the user had logged out of the application. It just required the right sequence of “Back” and “Refresh” to catch the password. And it was stunningly simple.
We did an informal poll to see how frequently we come across this vulnerability in our tests today. They have dropped from 50% of apps a year ago to less than 10% now. Sure, informal polls are unscientific, but the numbers suggest that more applications that get tested for security address the problem today. That’s good news.
Today Karmendra, geek, fellow-blogger, museum-enthusiast turns entrepreneur. He joins his friend Seemanta to found SecurEyes. Best wishes from humsab@paladion, KK, Seemanta!
Plynt provides penetration testing and code review services to clients worldwide. If you are interested, please contact us for a quote. We’ll get back to you within one working day.Add yours.closed for this post.
Monthly Archives
- September 2008
- August 2008
- July 2008
- May 2008
- April 2008
- March 2008
- January 2008
- December 2007
- November 2007
- April 2007
- March 2007
- February 2007
- January 2007
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
Syndication
You can read full entries of Palisade Blog using an RSS reader. Use this link —




Hi,
I just got this link when i was searching in google with my name, I am a CS Enggineer just passed out this year and currently working at Indian Institute of Science, I read ur article ... it was good knowing that. I was just thinking of my solution to this problem, I will tell u when i build upon it.
All the very best to you Karmendra K.