This is an archived snapshot of W3C's public bugzilla bug tracker, decommissioned in April 2019. Please see the home page for more details.

Bug 25809 - Security issue: Abuse of "call me" URLs
Summary: Security issue: Abuse of "call me" URLs
Status: RESOLVED FIXED
Alias: None
Product: WebRTC Working Group
Classification: Unclassified
Component: Media Capture and Streams (show other bugs)
Version: unspecified
Hardware: PC All
: P2 normal
Target Milestone: ---
Assignee: Adam Bergkvist
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-19 18:20 UTC by Cullen Jennings
Modified: 2014-09-25 14:44 UTC (History)
6 users (show)

See Also:


Attachments

Description Cullen Jennings 2014-05-19 18:20:59 UTC
The security section should warn people about the risk of having a website that took URL like www.example.com?call=evil or www.example.com?call=+1900-PAY-FLUF. If  the site automatically makes that call if example.com had permission, then an advertisement network can display an add that redirects you to this and the users camera will sending stuff and sending it to an attacker.
Comment 1 Harald Alvestrand 2014-06-09 07:43:38 UTC
Changing subject for better readability.
Comment 2 Justin Uberti 2014-06-10 00:23:52 UTC
Agree, was thinking about this the other day. We will make changes to our sample apps to prevent this.
Comment 3 Adam Bergkvist 2014-07-03 05:26:00 UTC
The receivers of this info would be web developers, rather than implementers of the spec. Where do we put that kind of info
Comment 4 Dominique Hazael-Massieux 2014-08-28 09:38:07 UTC
Proposed fix: https://github.com/w3c/mediacapture-main/pull/9

I'm also suggesting more thorough protections against this type of abuse:
http://lists.w3.org/Archives/Public/public-media-capture/2014Aug/0187.html
Comment 5 Stefan Hakansson LK 2014-09-16 14:17:30 UTC
In the interest of making progress, I propose we add a note of that more feedback is wanted from webappsec on this.
Comment 6 Dominique Hazael-Massieux 2014-09-16 15:29:04 UTC
(In reply to Stefan Hakansson LK from comment #5)
> In the interest of making progress, I propose we add a note of that more
> feedback is wanted from webappsec on this.

I've updated PR 9 to that effect.
Comment 7 Cullen Jennings 2014-09-25 14:44:29 UTC
Merged dom's PR to fix this.