SlideShare a Scribd company logo
ABUSINGTARGET
@s4n7h0
StatutoryWarning
Disclaimer
“This presentation is purely intended for knowledge sharing.The
presenter’s intention is not to show any unknown or zero day security bugs.
I strongly encourage responsible disclosure if you encounter any similar
issues in the wide internet range. Examples shown in the live demo is only
for educational purpose.”
Target
■ <a href=“http://foo.com” target=“_blank”>click here to foo</a>
target _blank
_parent
_self
_top
framename
Specifies where to open the
linked document
Source: http://www.w3schools.com/tags/tag_a.asp
How it works (technically)
■ User clicks on the hyperlink.
■ The URL loads in new tab
■ window.opener will have reference hook to parent tab.
window.opener
■ Returns a reference to the window that opened this current window.
■ Windows Phone browser does not support window.opener (tested with
Microsoft Edge 25.10586.36.0). It is also not supported in IE if the
opener is in a different security zone. (https://developer.mozilla.org/)
Source: http://www.w3schools.com/
Let’s see things in action
Alright,What’s the fix ?
■ The issue is in client side, so does the fix too.
■ Server can not control this.
■ Security headers such as CSP, XXS Protection, etc., doesn't help.
■ URL forwarding doesn't seems to have this issue so far.
■ rel="noopener noreferrer”
Final thoughts
■ Also known as _blank vulnerability. But somehow got ignored.
■ There could be other sites that might have same issues. Go, hunt and
report them responsibly.
■ While some consider this as a security risk, others don't.Take your own
mature decision on it.
Twitter: @s4n7h0
Email: i.am.s4n7h0@gmail.com

More Related Content

KEY
Mozilla Crash Analysis and Reporting
PDF
How To Prevent Virus Part1
PPTX
How to remove trending upnow pop up
PPTX
Toryvis Project
POT
Kevin 7b Dangers in E-mails
PPTX
Middleware hacking
PDF
Apt sharing tisa protalk 2-2554
PPTX
Dll Hijacking
Mozilla Crash Analysis and Reporting
How To Prevent Virus Part1
How to remove trending upnow pop up
Toryvis Project
Kevin 7b Dangers in E-mails
Middleware hacking
Apt sharing tisa protalk 2-2554
Dll Hijacking

Viewers also liked (19)

PPTX
Advanced Persistent Threats (APTs) - Information Security Management
PDF
Null 11 june_Malware CNC: Advance Evasion techniques_by Avkash k and dhawal shah
PPTX
Introduction to Advanced Persistent Threats (APT) for Non-Security Engineers
PPT
DLL Hijacking
PPTX
Advanced persistent threat (apt)
PDF
APT(Advanced Persistent Threats) & strategies to counter APT
PDF
Slide Deck Class Session 8 – FRSecure CISSP Mentor Program
PPTX
Slide Deck CISSP Class Session 5
PDF
Slide Deck - CISSP Mentor Program Class Session 1
PDF
Slide Deck CISSP Class Session 7
PDF
Slide Deck Class Session 10 – FRSecure CISSP Mentor Program
PDF
Slide Deck CISSP Class Session 4
PDF
Slide Deck CISSP Class Session 3
PDF
Slide Deck CISSP Class Session 2
PDF
Slide Deck Class Session 11 – FRSecure CISSP Mentor Program
PDF
Slide Deck CISSP Class Session 6
PDF
Cyber Security 2017 Challenges
PDF
Cyber security threats for 2017
PDF
2017 Cybersecurity Predictions
Advanced Persistent Threats (APTs) - Information Security Management
Null 11 june_Malware CNC: Advance Evasion techniques_by Avkash k and dhawal shah
Introduction to Advanced Persistent Threats (APT) for Non-Security Engineers
DLL Hijacking
Advanced persistent threat (apt)
APT(Advanced Persistent Threats) & strategies to counter APT
Slide Deck Class Session 8 – FRSecure CISSP Mentor Program
Slide Deck CISSP Class Session 5
Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck CISSP Class Session 7
Slide Deck Class Session 10 – FRSecure CISSP Mentor Program
Slide Deck CISSP Class Session 4
Slide Deck CISSP Class Session 3
Slide Deck CISSP Class Session 2
Slide Deck Class Session 11 – FRSecure CISSP Mentor Program
Slide Deck CISSP Class Session 6
Cyber Security 2017 Challenges
Cyber security threats for 2017
2017 Cybersecurity Predictions
Ad

Similar to Abusing Target (15)

PPT
Web 2 For English
PPT
Web 2 For English1.1
ODP
How Does Open Source Software Facilitate Education?
ODP
(ISC)2 Cincinnati Tri-State Chapter: Phishing Forensics - Is it just suspicio...
DOCX
These discussions should help you understand what a primary so
PPT
Open Source In Education - Tech&Learning Conference Presentation '09
ODP
Foss Presentation
PDF
Web design , accessibility, and usability tips in Blackboard
PPT
Open Source Shareware Freeware
PDF
HTML5 Security For Beginners
PPTX
Examples Of Online Promotion - HEA Professional Presences For Academics Works...
PDF
Reversing & malware analysis training part 10 exploit development basics
PPTX
Browser Hacking For Fun and Profit | Null Bangalore Meetup 2019 | Divyanshu S...
ODP
BSides Indianapolis: Phishing Forensics - Is it just suspicious or is it mali...
PPTX
10 eLearning tools
Web 2 For English
Web 2 For English1.1
How Does Open Source Software Facilitate Education?
(ISC)2 Cincinnati Tri-State Chapter: Phishing Forensics - Is it just suspicio...
These discussions should help you understand what a primary so
Open Source In Education - Tech&Learning Conference Presentation '09
Foss Presentation
Web design , accessibility, and usability tips in Blackboard
Open Source Shareware Freeware
HTML5 Security For Beginners
Examples Of Online Promotion - HEA Professional Presences For Academics Works...
Reversing & malware analysis training part 10 exploit development basics
Browser Hacking For Fun and Profit | Null Bangalore Meetup 2019 | Divyanshu S...
BSides Indianapolis: Phishing Forensics - Is it just suspicious or is it mali...
10 eLearning tools
Ad

More from nullowaspmumbai (20)

PDF
ELK in Security Analytics
PPTX
Switch security
PPTX
Radio hacking - Part 1
PPTX
How I got my First CVE
PPTX
Power forensics
PPTX
Infrastructure security & Incident Management
PPTX
Middleware hacking
PPTX
Internet censorship circumvention techniques
PPTX
How i got my first cve
PPTX
Adversarial machine learning updated
PPTX
PPTX
Adversarial machine learning
PDF
NTFS Forensics
PPTX
Drozer - An Android Application Security Tool
PDF
Ganesh naik linux_kernel_internals
PDF
Buffer overflow null
PDF
Null Mumbai Meet_Android Reverse Engineering by Samrat Das
PDF
Null mumbai Session on ransomware by_Aditya Jamkhande
PDF
Null mumbai news bytes by Rahul Tulaskar
ELK in Security Analytics
Switch security
Radio hacking - Part 1
How I got my First CVE
Power forensics
Infrastructure security & Incident Management
Middleware hacking
Internet censorship circumvention techniques
How i got my first cve
Adversarial machine learning updated
Adversarial machine learning
NTFS Forensics
Drozer - An Android Application Security Tool
Ganesh naik linux_kernel_internals
Buffer overflow null
Null Mumbai Meet_Android Reverse Engineering by Samrat Das
Null mumbai Session on ransomware by_Aditya Jamkhande
Null mumbai news bytes by Rahul Tulaskar

Recently uploaded (20)

PPTX
OMC Textile Division Presentation 2021.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
cloud_computing_Infrastucture_as_cloud_p
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Programs and apps: productivity, graphics, security and other tools
PPTX
A Presentation on Artificial Intelligence
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PPTX
Spectroscopy.pptx food analysis technology
PDF
August Patch Tuesday
OMC Textile Division Presentation 2021.pptx
MIND Revenue Release Quarter 2 2025 Press Release
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
Network Security Unit 5.pdf for BCA BBA.
Agricultural_Statistics_at_a_Glance_2022_0.pdf
SOPHOS-XG Firewall Administrator PPT.pptx
Spectral efficient network and resource selection model in 5G networks
cloud_computing_Infrastucture_as_cloud_p
TLE Review Electricity (Electricity).pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Programs and apps: productivity, graphics, security and other tools
A Presentation on Artificial Intelligence
Group 1 Presentation -Planning and Decision Making .pptx
Building Integrated photovoltaic BIPV_UPV.pdf
Assigned Numbers - 2025 - Bluetooth® Document
Spectroscopy.pptx food analysis technology
August Patch Tuesday

Abusing Target

  • 3. Disclaimer “This presentation is purely intended for knowledge sharing.The presenter’s intention is not to show any unknown or zero day security bugs. I strongly encourage responsible disclosure if you encounter any similar issues in the wide internet range. Examples shown in the live demo is only for educational purpose.”
  • 4. Target ■ <a href=“http://foo.com” target=“_blank”>click here to foo</a> target _blank _parent _self _top framename Specifies where to open the linked document Source: http://www.w3schools.com/tags/tag_a.asp
  • 5. How it works (technically) ■ User clicks on the hyperlink. ■ The URL loads in new tab ■ window.opener will have reference hook to parent tab.
  • 6. window.opener ■ Returns a reference to the window that opened this current window. ■ Windows Phone browser does not support window.opener (tested with Microsoft Edge 25.10586.36.0). It is also not supported in IE if the opener is in a different security zone. (https://developer.mozilla.org/) Source: http://www.w3schools.com/
  • 7. Let’s see things in action
  • 8. Alright,What’s the fix ? ■ The issue is in client side, so does the fix too. ■ Server can not control this. ■ Security headers such as CSP, XXS Protection, etc., doesn't help. ■ URL forwarding doesn't seems to have this issue so far. ■ rel="noopener noreferrer”
  • 9. Final thoughts ■ Also known as _blank vulnerability. But somehow got ignored. ■ There could be other sites that might have same issues. Go, hunt and report them responsibly. ■ While some consider this as a security risk, others don't.Take your own mature decision on it. Twitter: @s4n7h0 Email: [email protected]