guardianproject / Orweb

We are EOL this project. Please use Lightning Browser or wait for Orfox instead
https://guardianproject.info/2015/06/30/orfox-aspiring-to-bring-tor-browser-to-android/
Other
91 stars 45 forks source link

Wrong or spoofable URL in the address bar or title #59

Open deadc0de opened 9 years ago

deadc0de commented 9 years ago

If a webpage contains a HTTP redirect, the wrong URL is shown in the address bar in the end. You can try it with e.g. https://tinyurl.com/161 which redirects to http://www.google.com/ . During loading the forwarded URL is displayed. Afterwards the title bar will show page title | original URL. The address bar does also contain the original instead of the actual URL.

The title bar showing the URL is also vulnerable to address spoofing with enabled JavaScript. In my tests the address could be spoofed with example three, four, five and seven. Examples were taken from here: https://ios.browsr-tests.com/alt/native.abs.php