Browser password input box value anti-theft method, device and equipment and medium
By monitoring the browser JS API and setting whitelist plug-ins, illegal requests are intercepted, solving the security risks of the Chromium browser's Webdriver and plug-ins, ensuring the security of user passwords, and improving the security of the browser.
Patent Information
- Application Number
- CN202510655069.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-09-26
Smart Images

Figure CN120705860A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a method, device, equipment and medium for preventing the value of a browser password input box from being stolen. Background Art
[0002] In today's internet environment, network security has always been a focus of user attention. While Chromium-based browsers offer numerous advantages in functionality and performance, they also present some significant security risks, as listed below:
[0003] 1. Webdriver Security Vulnerabilities
[0004] Furthermore, existing Webdrivers also have certain security vulnerabilities. Webdriver is a tool used to automate browser behavior testing. It uses the Chrome browser's API to perform various operations on browser page elements, including obtaining data on the page. However, if this functionality is exploited by malicious actors, they could write malicious scripts and use Webdriver to obtain the value in the password field during user login. For example, in some internal corporate office system login scenarios, if a malicious Webdriver script is implanted in the system, employees' login passwords could be easily stolen, threatening the security of important internal information and data.
[0005] 2. Plugin Security Risks
[0006] While the existing Chrome browser plugin mechanism offers users a wealth of expanded functionality, it also carries hidden risks. Some criminals may develop malicious Chrome plugins. Once installed, these plugins can unknowingly obtain sensitive information entered into password fields when logging into websites. For example, when a user logs in to an e-commerce website, a malicious plugin might silently intercept the user's account and password input in the background and then transmit this information to criminals, seriously threatening the user's account security and potentially leading to a range of serious consequences, including account theft and personal financial loss.
[0007] For ordinary users, if they accidentally install illegal plug-ins or are infected with a Trojan virus, their passwords and other critical information are very likely to be stolen when accessing various websites using a Chromium-based browser. Once a password is stolen, the user's personal privacy, financial security, and the security of their accounts on various online platforms are all at great risk. For example, a user's social media account could be maliciously logged into and inappropriate information could be posted, or their online banking account could be used for illegal transfers, causing significant losses and trouble to the user.
[0008] In summary, these problems in plug-in management and Webdriver security in browsers developed based on Chromium have posed a serious threat to users' network security. Effective measures are urgently needed to resolve them in order to protect the legitimate rights and interests of users and the security and stability of cyberspace. Summary of the Invention
[0009] The technical problem to be solved by the present invention is to provide a method, device, equipment and medium for preventing the theft of the value of a browser password input box, thereby achieving the security of user passwords in a Chromium-based browser.
[0010] In a first aspect, the present invention provides a method for preventing the theft of values in a browser password input box, which is used in a browser developed based on Chromium, and specifically comprises the following steps:
[0011] Step 1: Monitor the js api execution of the current input.value to see if it is a request for input type=password. If so, proceed to step 2; if not, continue monitoring.
[0012] Step 2: Get the sandbox of the JS runtime and get the URL address of the JS in the current execution context;
[0013] Step 3: If the URL address starts with http or https, return the value corresponding to the request;
[0014] If the url address is empty, the request will be intercepted and the set value will be returned.
[0015] In a second aspect, the present invention provides a browser password input box value theft prevention device for a browser developed based on Chromium, specifically comprising the following modules:
[0016] The monitoring module monitors whether the js api execution of the current input.value is a request for input type=password. If so, it enters the URL acquisition module; if not, it continues monitoring;
[0017] Get the url module, get the JS runtime sandbox, and get the JS url address of the current execution context;
[0018] Anti-theft module, if the URL address starts with http or https, it returns the value corresponding to the request;
[0019] If the url address is empty, the request will be intercepted and the set value will be returned.
[0020] In a third aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the first aspect when executing the program.
[0021] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the method described in the first aspect when the program is executed by a processor.
[0022] One or more technical solutions provided by the present invention have at least the following technical effects or advantages:
[0023] The present invention makes the Chromium-based browser more secure by disabling the access of the password box value through the webdriver, and can still ensure the security of the password even if a Trojan horse is infected;
[0024] The present invention also assigns a value to the password acquisition box by setting a whitelist plug-in, which can more safely protect the user password from being stolen by the plug-in.
[0025] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0027] Figure 1 This is a flowchart of the method in Example 1 of the present invention;
[0028] Figure 2 This is a schematic diagram of the structure of the device in Example 2 of the present invention. DETAILED DESCRIPTION
[0029] The embodiments of the present application provide a method, apparatus, device, and medium for preventing the theft of values in a browser password input box, and implement the security of user passwords in a Chromium-based browser by modifying the input element and stack (js execution stack) related methods at the bottom layer of Chromium.
[0030] The technical solutions in the embodiments of this application have the following general ideas:
[0031] Configure the plug-in whitelist and webdriver access control switch;
[0032] Start the fingerprint browser and pass the whitelist to the fingerprint browser.
[0033] When the plug-in wants to access the value of the password box, it will intercept and determine whether it is in the whitelist. If it is in the whitelist, it will be released, otherwise it will return empty.
[0034] When the webdriver accesses the password box, intercept and determine whether the webdriver is allowed to access it. If it is allowed, it will return empty.
[0035] The specific implementation is as follows:
[0036] 1. In the String HTMLInputElement::Value() method, determine that the current input.value JS API is executing a request for input type=password. We only need to intercept the password box of type=password (Chromium does not have it, so we need to add it)
[0037] ValueMode value_mode=input_type_->GetValueMode(); / / Get the input type of the current request value
[0038] if(input_type_->IsPasswordInputType()&&value_mode==ValueMode::kValue){ / / Interception type=password
[0039] / / Intercept here
[0040] }
[0041] 2. Add a method to get the js call stack in the current code file. (Chromium itself does not have it, so we need to add it)
[0042] 2.1 Get the isolated sandbox of JS runtime
[0043] v8::Isolate*isolate=GetExecutionContext()->GetIsolate();
[0044] 2.2 Get the execution context of the JS runtime and the security source of the JS in the current execution context
[0045] blink::ExecutionContext*execution_context=GetExecutionContext();
[0046] const blink::SecurityOrigin*security_origin=execution_context->GetSecurityOrigin();
[0047] 2.3 Determine the full URL address of the security source of the currently running js. If the URL address of the js starts with http or https, we will directly release it. If not, we will proceed to the next step 2.4 interception.
[0048] v8::Local <v8::string>script_name=frame->GetScriptNameOrSourceURL();
[0049] String script_url_str=ToCoreStringWithNullCheck(isolate,script_name);
[0050] / / script_url_str: empty, for webdriver, those starting with chrome-extension: / / are plugins, those starting with http or https are the website's own JS
[0051] if(script_url_str.empty()||!script_url_str.StartsWithIgnoringASCIICase("http")){ / / Intercept js that does not start with http or https, which needs to be intercepted
[0052] / / Intercept here
[0053] };
[0054] 2.4 Determine whether the access permission control of webdriver is allowed. If it is set to inaccessible and script_url-str is empty, then return empty directly. Otherwise, we proceed to the next step 2.5 interception
[0055] if(!config.webdriver&&script_url_str.empty()){ / / webdriver is set to not allow
[0056] return ""; / / return empty
[0057] }
[0058] 2.5 Check the plugin whitelist. If the current script_url is a plugin from the whitelist, it will be allowed to pass directly. Otherwise, it will be intercepted and return empty.
[0059] if(script_url_str in config.whitelist){
[0060] return normal value
[0061] }else{
[0062] return ""
[0063] }.
[0064] Example 1
[0065] like Figure 1 As shown, this embodiment provides a method for preventing the value of a browser password input box from being stolen, which is used in a browser developed based on Chromium, and specifically includes the following steps:
[0066] Step 1: Monitor the js api execution of the current input.value to see if it is a request for input type=password. If so, proceed to step 2; if not, continue monitoring.
[0067] Step 2: Get the sandbox of the JS runtime and get the URL address of the JS in the current execution context;
[0068] Step 3: If the URL address starts with http or https, return the value corresponding to the request;
[0069] If the url address is empty, the request will be intercepted and the set value will be returned.
[0070] In this embodiment, preferably, step 1 specifically includes: determining in the String HTMLInputElement::Value() method whether the current input.value js api execution is a request for input of type=password; if so, proceed to step 2; otherwise, continue monitoring.
[0071] In this embodiment, preferably, step 2 is specifically as follows:
[0072] Get the isolated sandbox of the JS runtime:
[0073] v8::Isolate*isolate=GetExecutionContext()->GetIsolate();
[0074] Get the execution context of the JS runtime and get the JS URL address based on the execution context:
[0075] blink::ExecutionContext*execution_context=GetExecutionContext();
[0076] const blink::SecurityOrigin*security_origin=execution_context->GetSecurityOrigin().
[0077] In this embodiment, preferably, step 3 specifically includes: setting a whitelist of plug-ins in the browser, and returning a value corresponding to the request if the URL address begins with http or https;
[0078] If the url address is empty, intercept the request and return the set value;
[0079] If the url address is not empty and does not start with http or https, the request is initiated by a plug-in. Then, it is determined whether the plug-in is in the whitelist. If it is, the value corresponding to the request is returned. If not, the request is intercepted and the set value is returned.
[0080] Based on the same inventive concept, this application also provides a device corresponding to the method in Example 1, see Example 2 for details.
[0081] Example 2
[0082] like Figure 2 As shown, in this embodiment, a browser password input box value theft prevention device is provided, which is used in a browser developed based on Chromium, and specifically includes the following modules:
[0083] The monitoring module monitors whether the js api execution of the current input.value is a request for input type=password. If so, it enters the URL acquisition module; if not, it continues monitoring;
[0084] Get the url module, get the JS runtime sandbox, and get the JS url address of the current execution context;
[0085] Anti-theft module, if the URL address starts with http or https, it returns the value corresponding to the request;
[0086] If the url address is empty, the request will be intercepted and the set value will be returned.
[0087] In this embodiment, preferably, the monitoring module specifically determines whether the current input.value js api execution is a request for input type=password in the String HTMLInputElement::Value() method, if so, enters the URL acquisition module, otherwise, continues monitoring.
[0088] In this embodiment, preferably, the url acquisition module is specifically:
[0089] Get the isolated sandbox of the JS runtime:
[0090] v8::Isolate*isolate=GetExecutionContext()->GetIsolate();
[0091] Get the execution context of the JS runtime and get the JS URL address based on the execution context:
[0092] blink::ExecutionContext*execution_context=GetExecutionContext();
[0093] const blink::SecurityOrigin*security_origin=execution_context->GetSecurityOrigin().
[0094] In this embodiment, preferably, the anti-theft module specifically: sets a whitelist of plug-ins in the browser, and returns a value corresponding to the request if the URL address begins with http or https;
[0095] If the url address is empty, intercept the request and return the set value;
[0096] If the url address is not empty and does not start with http or https, the request is initiated by a plug-in. Then, it is determined whether the plug-in is in the whitelist. If it is, the value corresponding to the request is returned. If not, the request is intercepted and the set value is returned.
[0097] Since the device described in the second embodiment of the present invention is used to implement the method of the first embodiment of the present invention, those skilled in the art will be able to understand the specific structure and variations of the device based on the method described in the first embodiment of the present invention, and therefore will not be described in detail here. All devices used in the method of the first embodiment of the present invention fall within the scope of protection of the present invention.
[0098] Based on the same inventive concept, this application provides an electronic device embodiment corresponding to the first embodiment, see the third embodiment for details.
[0099] Example 3
[0100] This embodiment provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, any implementation method in the first embodiment can be implemented.
[0101] Since the electronic device described in this embodiment is the device used to implement the method in Example 1 of this application, based on the method described in Example 1 of this application, those skilled in the art will be able to understand the specific implementation of the electronic device of this embodiment and its various variations. Therefore, how the electronic device implements the method in the embodiment of this application will not be described in detail here. As long as the device used by those skilled in the art to implement the method in the embodiment of this application falls within the scope of protection to be provided by this application.
[0102] Based on the same inventive concept, this application provides a storage medium corresponding to Example 1, see Example 4 for details.
[0103] Example 4
[0104] This embodiment provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, any implementation method in the first embodiment can be implemented.
[0105] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0106] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0107] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0108] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0109] Although the specific embodiments of the present invention are described above, those skilled in the art should understand that the specific embodiments described are merely illustrative and are not intended to limit the scope of the present invention. Equivalent modifications and changes made by those skilled in the art in accordance with the spirit of the present invention should be included within the scope of protection of the claims of the present invention.
Claims
1. A method for preventing the value of a browser password input box from being stolen, characterized in that: For browsers developed based on Chromium, the steps include: Step 1: Monitor the js api execution of the current input.value to see if it is a request for input type=password. If so, proceed to step 2; if not, continue monitoring. Step 2: Get the sandbox of the JS runtime and get the URL address of the JS in the current execution context; Step 3: If the URL address starts with http or https, return the value corresponding to the request; If the url address is empty, the request will be intercepted and the set value will be returned.
2. A browser password input box value theft prevention method according to claim 1, characterized in that: The step 1 is specifically as follows: in the String HTMLInputElement::Value() method, it is determined whether the jsapi execution of the current input.value is a request for input of type=password; if so, the process proceeds to step 2; otherwise, the process continues monitoring.
3. The method for preventing the value of a browser password input box from being stolen according to claim 1, wherein: The step 2 is specifically as follows: Get the isolated sandbox of the JS runtime: v8::Isolate*isolate=GetExecutionContext()->GetIsolate(); Get the execution context of the JS runtime and get the JS URL address based on the execution context: blink::ExecutionContext*execution_context=GetExecutionContext(); const blink::SecurityOrigin*security_origin=execution_context->GetSecurityOrigin().
4. The method for preventing theft of a browser password input box value according to claim 1, characterized in that: The step 3 is specifically as follows: setting a whitelist of plug-ins in the browser, and returning the value corresponding to the request if the URL address begins with http or https; If the url address is empty, intercept the request and return the set value; If the url address is not empty and does not start with http or https, the request is initiated by a plug-in. Then, it is determined whether the plug-in is in the whitelist. If it is, the value corresponding to the request is returned. If not, the request is intercepted and the set value is returned.
5. A device for preventing theft of values in a browser password input box, characterized in that: Used for browsers developed based on Chromium, specifically including the following modules: The monitoring module monitors whether the js api execution of the current input.value is a request for input type=password. If so, it enters the URL acquisition module; if not, it continues monitoring; Get the url module, get the JS runtime sandbox, and get the JS url address of the current execution context; Anti-theft module, if the URL address starts with http or https, it returns the value corresponding to the request; If the url address is empty, the request will be intercepted and the set value will be returned.
6. The anti-theft device for a browser password input box according to claim 5, characterized in that: The monitoring module specifically determines whether the current input.value js api execution is a request for input type=password in the String HTMLInputElement::Value() method. If so, it enters the URL acquisition module; otherwise, it continues monitoring.
7. The anti-theft device for a browser password input box according to claim 5, characterized in that: The specific module for obtaining URL is: Get the isolated sandbox of the JS runtime: v8::Isolate*isolate=GetExecutionContext()->GetIsolate(); Get the execution context of the JS runtime and get the JS URL address based on the execution context: blink::ExecutionContext*execution_context=GetExecutionContext(); const blink::SecurityOrigin*security_origin=execution_context->GetSecurityOrigin().
8. The device for preventing theft of a browser password input box according to claim 5, characterized in that: The anti-theft module specifically sets a whitelist of plug-ins in the browser, and returns the value corresponding to the request if the URL address begins with http or https; If the url address is empty, intercept the request and return the set value; If the url address is not empty and does not start with http or https, the request is initiated by a plug-in. Then, it is determined whether the plug-in is in the whitelist. If it is, the value corresponding to the request is returned. If not, the request is intercepted and the set value is returned.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 4 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.