Password managers that leak logins in clickjacking attacks

Whatever the PWM you are using please read the article below. Eleven PWM’s were tested for this vulnerability and found to be vulnerable to at least one of the attack elements tested. Two were “informative” with a fix, three “ in progress”, five fixed and one “no reply” from LogMeOnce.

5 Likes

Je viens de voir cette information et je m’interroge légitimement sur la fiabilité de Norton Password Manager. Je ne suis pas naïve, je sais très que tout logiciel contient des “failles de sécurité”.

Merci pour avoir partagé l’information.

Thank you for posting this article as I do think it is of some serious concern for all.

My reading of the article is that you must visit a malicious webpage that runs the malware and then can steal info from the password manager, Most likely it would be click bait to get you there via email or text.

Norton Safe Web might help to stop the connection to the malevolent web page. In any case this once again shows the vunerabilities of the web and how the individual is the primary line of defense and the software is the seconday line.

Let’s hope Norton can address this issue and provide some info.

Pour ma part, je n’utilise plus l’extension « safe web » depuis la version 24.4. Je la considère comme inutile depuis l’arrivée des nouvelles versions de Norton basées sur Avast (voir Support Avast - Défense du web)

Evidemment, ceci n’est que mon avis : chacun est libre d’avoir sa propre opinion.

1 Like

@Gayathri_R Does Norton have any feedback for this issue? Please advise.

SA

1 Like

related discussion:
https://www.wilderssecurity.com/threads/researcher-exposes-zero-day-clickjacking-vulnerabilities-in-major-password-managers.457770/

me too

================================================

Learn more about <Norton 360> Safe Web [here]
Configure <Norton 360> Safe Web settings [here]

=================================================

Web Shield blocks malicious websites, phishing attempts, and downloads that could potentially infect your device. Web Shield prevents online attacks by blocking malware, fake websites, dangerous URLs, and scams.

Web Shield protects your system from online threats by scanning data that is transferred between your device and the web. Web Shield works below the browser level, so it works with any browser and doesn’t require extensions.

Web Shield scans your data when you browse online. This safeguards your computer from malware. Web Shield blocks websites and prevents hackers from using your computer as a host when hacking into other computers.

Web Shield detects the most recent threats. It works in real-time, scanning files and programs as they’re opened or downloaded.

Web Shield intercepts web traffic before it hits the browser and runs it through a real-time scanner. Web Shield looks over web pages and checks them for threats before the page is loaded.

========================================

We’re hoping Norton publishes and maintains an online, current, in-depth, indexed, searchable, illustrated/videos…Norton 360 User Guide

Bonjour,

Je vous remercie pour les informations transmises. Mes paramètres Navigation Web sécurisée sont tous bien activés.