Browser Auth Pishing Attack with embedded images

Jan 12, 2015
Steps to reproduce


Repro Steps:

Vulnerability Test Case

For example i have here an image that can be used on any site - It will ask you for authentication when the image try to load.
The image is generated by a server side PHP script and can therefore grab and save your credentials to a database or whatever.
Don’t panic, this image is for demonstration only and does not log any credentials, i’m a white hat.

<img src="" alt=""/>

A external demonstration page where you see it in action

Expected Results:

Never ask for auth windows in embedded images or other embedded stuff.

Actual Results:

Dev Channel specific:



