This writeup describes a vulnerability in Google Chrome (24.0.1312.57) where HTTP Basic Authentication is silently processed without user alerts when injected into HTML tags. The issue allows brute-force attacks on routers with default credentials, enabling remote administration and DNS manipulation.
Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target:Google Chrome 24.0.1312.57
No auth needed
Prerequisites:Access to a target network with vulnerable routers · Default or weak credentials on the router