By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
softwareprosoftwarepro
  • Home
  • A/B Testing Tools
    • Accounting Software
    • Ad Serving & Retargeting Platforms
    • All-in-One Marketing Platforms
    • Applicant Tracking Systems (ATS)
    • Business Intelligence (BI) Tools
    • Cloud Storage Systems
    • Collaboration Tools
    • Content Management(CMS)
    • Corporate Learning Management
  • Agile
    • AI
    • Big Data
    • Cloud
    • Database
    • Devops
    • Integration
    • IoT
    • Java
    • Guest Posting
  • Customer Relationship (CRM)
    • Email Marketing Software
    • Fraud Detection Software
    • Help Desk Software
    • HR Management Software
    • Integration Platform as a Software
    • Marketing Automation Software
    • Network Performance Monitoring
    • Payroll Software
  • Project Management Software
    • SEO Software
    • Social Media Management Tools
    • Talent Intelligence Tools Solutions
    • Talent Management
    • Web Analytics Tools
    • Web and Video Conferencing
    • Workforce Analytics Software
    • Workforce Management Software
  • Accessibility Testing Tools
    • Agile Development Software
    • Augmented Development Platforms
    • Automation Testing Tools
    • Batch Management Software
    • Beta Testing Software
    • Bug Tracking Software
  • More
    • Microservices
    • Open Source
    • Performance
    • Security
    • Web Dev
    • Automotive
    • Business
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
Search
  • Consumer & Gadgets
  • Electronics & Semiconductors
  • Energy & Green Tech
  • Engineering
  • Hardware
  • Hi Tech & Innovation
  • Internet
  • Machine learning & AI
© 2022 Softwareproz.com/knowledge resources for software developers. All Rights Reserved.
Reading: Hackers might be able to crack this top password manager and steal your logins
Share
Notification Show More
Latest News
The Samsung Galaxy S24 Ultra could be in line for a major display upgrade
Audio Digital Home Gaming Home Cinema Mobile Computing
Thrilled by The Night Agent? Watch these 7 spy shows while we wait for season 2
Audio Digital Home Gaming Home Cinema Mobile Computing
Google promises to unleash more of Bard’s potential in the ‘next week’
Audio Digital Home Gaming Home Cinema Mobile Computing
Google AirTags: why the incoming Apple rivals could take over the world
Audio Digital Home Gaming Home Cinema Mobile Computing
How To Perform Sentiment Analysis and Classification on Text (In Java)
Agile AI Big Data Cloud Database Devops Integration IoT Java Microservices Open Source Performance Security Web Dev
Aa
softwareprosoftwarepro
Aa
Search
  • Home
  • A/B Testing Tools
    • Accounting Software
    • Ad Serving & Retargeting Platforms
    • All-in-One Marketing Platforms
    • Applicant Tracking Systems (ATS)
    • Business Intelligence (BI) Tools
    • Cloud Storage Systems
    • Collaboration Tools
    • Content Management(CMS)
    • Corporate Learning Management
  • Agile
    • AI
    • Big Data
    • Cloud
    • Database
    • Devops
    • Integration
    • IoT
    • Java
    • Guest Posting
  • Customer Relationship (CRM)
    • Email Marketing Software
    • Fraud Detection Software
    • Help Desk Software
    • HR Management Software
    • Integration Platform as a Software
    • Marketing Automation Software
    • Network Performance Monitoring
    • Payroll Software
  • Project Management Software
    • SEO Software
    • Social Media Management Tools
    • Talent Intelligence Tools Solutions
    • Talent Management
    • Web Analytics Tools
    • Web and Video Conferencing
    • Workforce Analytics Software
    • Workforce Management Software
  • Accessibility Testing Tools
    • Agile Development Software
    • Augmented Development Platforms
    • Automation Testing Tools
    • Batch Management Software
    • Beta Testing Software
    • Bug Tracking Software
  • More
    • Microservices
    • Open Source
    • Performance
    • Security
    • Web Dev
    • Automotive
    • Business
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
Follow US
  • Consumer & Gadgets
  • Electronics & Semiconductors
  • Energy & Green Tech
  • Engineering
  • Hardware
  • Hi Tech & Innovation
  • Internet
  • Machine learning & AI
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
softwarepro > Blog > Audio > Hackers might be able to crack this top password manager and steal your logins
AudioDigital HomeGamingHome CinemaMobile Computing

Hackers might be able to crack this top password manager and steal your logins

Last updated: 2023/03/09 at 3:07 PM
Share
SHARE

One of the most popular free password managers, has a major security flaw that could allow hackers to steal your credentials in an identity theft attack.

The autofill feature in the Bitwarden open-source password manager is the root of the problem, allowing bad inline frames (iframes) that are contained within trusted websites to capture your login details.

Security analysis firm Flashpoint discovered the flaw, but claims Bitwarden knew about it as far back as 2018, but chose to ignore it in favor of allowing its continued use on popular websites with iframes.  

Iframe hack

Iframes are HTML elements that are used to embed another webpage within the current one. They are commonly used for advertisements, web analytics, videos and interactive content.

Flashpoint discovered that when using the autofill feature – which is turned off by default in Bitwarden – on a webpage with an iframe, the credentials are automatically filled out on the parent page and then also on forms within the iframe page. And if this is a malicious iframe controlled by hackers, then they can steal your credentials. Even if the iframe is from an external domain, this will still happen.

“While the embedded iframe does not have access to any content in the parent page, it can wait for input to the login form and forward the entered credentials to a remote server without further user interaction,” Flashpoint said.

read more

> Another top password manager is doing away with passwords

> Bitwarden vs 1Password: 2023 Features Comparison

> One of the best password managers around now offers an additional layer of protection

However, Flashpoint found that the risk of such an attack was low as many legitimate and popular websites do not contain iframes on their login pages. 

More of a concern, though, was that Bitwarden’s autofill feature would even operate on subdomains of base domains for which you have a saved username and password for.

These subdomains can be used in phishing scams, where threat actors create fake pages using subdomains of legitimate website to steal your details. Flashpoint says this is possible as “some content hosting providers allow hosting arbitrary content under a subdomain of their official domain, which also serves their login page”.

Free hosting sites allow for this kind of subdomain creation, but there are a lot of legitimate domains do not allow the registering of subdomains based on them. However, in this case, a subdomain could still be hijacked by a hacker.

Bitwarden does issue a warning when you go to turn on its autofill feature, stating that “compromised or untrusted websites could take advantage of this to steal credentials.”

Despite the risk of iframe exploitation being announced in November 2018, Bitwarden decided to keep the autofill feature on login pages with iframes, since many popular websites do use them, “for example icloud.com uses an iframe from apple.com”, Bitwarden told BleepingComputer.

However, when it comes to autofilling forms on subdomains, Bitwarden said it will be issuing an update in future to prevent autofill on hosting environments that allow this. 

Here are the best business password managers

You Might Also Like

The Samsung Galaxy S24 Ultra could be in line for a major display upgrade

Thrilled by The Night Agent? Watch these 7 spy shows while we wait for season 2

Google promises to unleash more of Bard’s potential in the ‘next week’

Google AirTags: why the incoming Apple rivals could take over the world

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share this Article
Facebook Twitter Copy Link Print
Share
Previous Article ‘Indirect prompt injection’ attacks could upend chatbots
Next Article The hidden costs of AI: Impending energy and resource strain
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow
banner banner
Create an Amazing Newspaper
Discover thousands of options, easy to customize layouts, one-click to import demo and much more.
Learn More

Latest News

The Samsung Galaxy S24 Ultra could be in line for a major display upgrade
Audio Digital Home Gaming Home Cinema Mobile Computing
Thrilled by The Night Agent? Watch these 7 spy shows while we wait for season 2
Audio Digital Home Gaming Home Cinema Mobile Computing
Google promises to unleash more of Bard’s potential in the ‘next week’
Audio Digital Home Gaming Home Cinema Mobile Computing
Google AirTags: why the incoming Apple rivals could take over the world
Audio Digital Home Gaming Home Cinema Mobile Computing
//

We influence 20 million users and is the number one business and technology news network on the planet

Quick Link

  • Audio
  • Digital Home
  • Emerging Technology
  • Enterprise Application
  • Gaming
  • Mobile and Wireless
  • Networking
  • Operating System
  • Photography Video Capture

Blog Categories

  • Environment
  • Health
  • science
  • Technology
  • Amazon
  • Analyst Insights
  • Android
  • Apple
  • Ecommerce

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!
softwareprosoftwarepro
Follow US

© 2022 Software Pro News Network. Software Pro Design Company. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Register Lost your password?