Autocomplete injection attack

Nethanel Gelernter, Amir Herzberg

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Autocomplete, a well-known feature in popular search engines, offers suggestions for search terms before the user has even completed typing their query. We present the autocomplete injection attack and its potential exploits. In this attack, a cross-site attacker injects terms into the autocomplete suggestions offered by a web-service to a victim user. The most popular web search engines are vulnerable to the attack, as well as other websites. Autocomplete injection can be exploited in multiple ways, including phishing, framing, illegitimate content-promotion and sometimes persistent cross-site scripting attacks. We evaluated the effectiveness of the attack with several experiments. Our results show the potential impact of the autocomplete injection attacks.

Original languageEnglish
Title of host publicationComputer Security - 21st European Symposium on Research in Computer Security, ESORICS 2016, Proceedings
EditorsSokratis Katsikas, Catherine Meadows, Ioannis Askoxylakis, Sotiris Ioannidis
PublisherSpringer Verlag
Pages512-530
Number of pages19
ISBN (Print)9783319457406
DOIs
StatePublished - 2016
Event21st European Symposium on Research in Computer Security, ESORICS 2016 - Heraklion, Greece
Duration: 26 Sep 201630 Sep 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9879 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st European Symposium on Research in Computer Security, ESORICS 2016
Country/TerritoryGreece
CityHeraklion
Period26/09/1630/09/16

Bibliographical note

Publisher Copyright:
© Springer International Publishing Switzerland 2016.

Funding

This work was supported by grant 1354/11 from the Israeli Science Foundation (ISF), and by grants from the Israeli Ministry of Science, Technology and Space.

FundersFunder number
Ministry of Science, Technology and Space
Israel Science Foundation

    Keywords

    • Autocomplete injection attack
    • Blackhat SEO
    • CSRF
    • Cross site scripting
    • Cross-site attacks
    • Cross-site framing
    • Persistent XSS
    • Phishing
    • Usable security
    • Web-security

    Fingerprint

    Dive into the research topics of 'Autocomplete injection attack'. Together they form a unique fingerprint.

    Cite this