Web browsers: critical security hole in Firefox closed
Summary
In August 2015 attackers exploited a hole in Firefox’s same-origin policy that only affected versions with the built-in PDF viewer. Code distributed via advertising on a Russian website sent local files to a server in Ukraine. It specifically looked for developer files: on Linux, for example, /etc/passwd, SSH configurations and shell histories; on Windows, FTP and Subversion configurations.
Ideas
- The attack ran in the local file context and could therefore read and upload files.
- The exploit left no traces on the computer.
- Mozilla advised changing passwords and keys in the affected files as a precaution.
- Ad blockers possibly protected users, because the code came via advertising.
Insights
- Developer and admin computers are particularly rewarding targets because of their credentials.
- A file viewer built into the browser enlarges the attack surface.
Facts
- The update appeared as Firefox 39.0.3 and ESR 38.1.1.
- Macs were not the target of the exploit that was discovered.
References
Critique
- The report relies solely on Mozilla’s account; how many users were affected remains open.
Recommendations
- Store SSH keys only with password protection and do not keep credentials in plain text in configuration files.
- After a possible data leak, change keys and passwords even without proof of misuse.
Links to the original source and the Web Archive open in a new tab.