Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 1st, 2012, 02:32 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,930
Lightbulb Browser POC's to test

Quote:
Yes, you can have fun with downloads

It is an important and little-known property of web browsers that one document can always navigate other, non-same-origin windows to arbitrary URLs; in more limited circumstances, even individual frames can be targeted.

http://lcamtuf.blogspot.ro/2012/05/y...downloads.html

Quote:
The old seamless switcharoo

This is hardly new, but illustrates the effectiveness of using data: or precached content to do the deed. Should work neatly in up-to-date browsers. You're probably fooling yourself if you think you'd reliably spot this happening to you in the wild.

http://lcamtuf.coredump.cx/switch

Quote:
All the top three browsers are currently vulnerable to this attack; some provide weak cues about the origin of the download, but in all cases, the prompt is attached to the wrong window - and the indicators seem completely inadequate.

You can check out the demo here:

http://lcamtuf.coredump.cx/fldl

They either didn't work, or didn't fool me. Try 'em & see how you fare

BTW - Tested on FFv3.6.14 with & without JavaScripting etc
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #2  
Old June 1st, 2012, 02:36 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Browser POC's to test

Obviously it didn't fool you, you tested yourself. It's like saying "I'm a chair... haha I don't believe that for a second."

Real world if someone on Wilders linked to "an important flash update" that was really a virus I'm fairly certain a large portion of this site would get infected.
__________________
  #3  
Old June 3rd, 2012, 03:25 AM
Tomwa Tomwa is offline
Regular Poster
 
Join Date: Feb 2010
Posts: 160
Default Re: Browser POC's to test

Link 1 did absolutely nothing, TorBrowser blocked both popups, and noscript asked for me to follow a redirect to Adobe.com but as the the windows of maliciousness were unable to open it was pointless though I can see the issue presented.

Link 2 was interesting in the fact that TorBrowser (My web browser) as Access to Memory and Disk cache is forbidden. This would be easily exploited in normal Firefox. I use TorBrowser for all my browsing but I have Waterfox limited to access only a specific list of Grooveshark/Youtube IPs (all other traffic is blocked and HTTP/S is blocked system wide and exceptions are made as necessary). This if anything should prove that cache access (As it is) is flawed and needs to be secured by ensuring only the site which cached the data may access it.

Link 3 is this the same as number one? Same thing happened:

1. Click button
2. Asked to redirect to adobe.com
3. Redirect
4. Adobe.com opens in new tab and becomes the focus
5. 2 Popups blocked on initial page.

I must say this was fun though.
__________________
KIS 2013 + LUA + SRP + SpywareBlaster + UAC Max + EMET Max + (Removed) Keyscrambler + Sandboxie + WinPatrol + PeerBlock + TrueCrypt (FDE 63 Char random ASCII key) + Tor (Privoxy + Polipo chain) + OpenDNS + HostsMan (MVPS + hpHosts (Ads/trackers)).
  #4  
Old June 15th, 2012, 06:30 AM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,052
Default Re: Browser POC's to test

3rd link- easily spotted from the firefox 13 'from' section in the download window, but yes most people would fall for this

could someone please explain what the second link is doing/showing?
__________________
Active@ Disk Image | 10 On-Demand Scanners

  #5  
Old June 15th, 2012, 04:07 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Browser POC's to test

The second link starts out as the legit webpage with the URL showing that website. It then changes after a few seconds. From the source:

Quote:
If you don't get it, banking.beaver-peak.us is a trusted banking website;
everything else is attacker-controlled. We begin by opening the legitimate
banking website, and giving the user enough time to examine the address bar.

There is a common misconception that changing the URL must result in a visible
page transition that alerts the user to foul play, but that's not the case.

PS. In older versions of Firefox, where the http:// prefix is not hidden,
this will look a bit less convincing due to the misalignment of URLs. Easy to
fix, but upgrade your browser already.

PPS. Bonus question: can you do something useful by flipping two pages
very rapidly, especially with history.*? What are the implications for
clickjacking & friends?
__________________
  #6  
Old June 16th, 2012, 10:20 AM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,052
Default Re: Browser POC's to test

Quote:
Originally Posted by Hungry Man
The second link starts out as the legit webpage with the URL showing that website. It then changes after a few seconds. From the source:
ok thanks
__________________
Active@ Disk Image | 10 On-Demand Scanners

  #7  
Old June 16th, 2012, 01:07 PM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,330
Default Re: Browser POC's to test

Nothing happened in the second link for me.
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #8  
Old June 17th, 2012, 10:07 AM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,583
Default Re: Browser POC's to test

You should see this address in the address bar, right?
banking.beaver-peak.us

In my case I see something else:
banking.coredump.cx/us/

Is the POC working then?
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:10 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums