Informatics evenings: Data in password managers at risk – Clickjacking is still alive and well

#Password #managers #clickjacking
Share

The lecture will present new security research and the "DOM-based extension clickjacking" technique, which targets browser extensions. The technique described is general and can be used on various types of web browser extensions. The research itself focused on the 11 most widely used password managers. The result was the discovery of several serious zero-day vulnerabilities that affected millions of users.

Was your password manager vulnerable too? How did password manager developers respond to the vulnerability? What could an attacker have gained? You will learn all this and much more in this lecture!

The event is part of the Informatics Evenings at FIT CTU series in cooperation with IEEE Young Professionals.

Marek Tóth

Marek Tóth is an Ethical Hacker (Penetration Tester). He deals with IT security, focusing primarily on finding security vulnerabilities in web applications. He has been actively interested in this area since 2018, searching for web vulnerabilities that could be exploited.

Marek Tóth has discovered a number of significant and widely publicized vulnerabilities, including on Seznam (article) and HeroHero (article). One of his latest achievements was the discovery of vulnerabilities in widely used password managers with a potential impact on tens of millions of users worldwide (article).



  Date and Time

  Location

  Hosts

  Registration



  • Add_To_Calendar_icon Add Event to Calendar
  • Thákurova 9
  • Czech Technical University in Prague
  • Prague, Czech Republic
  • Czech Republic 160 00
  • Room Number: T9:107

  • Contact Event Host
  • Starts 16 October 2025 11:42 PM UTC
  • Ends 19 October 2025 10:00 PM UTC
  • No Admission Charge