bk99.de entertain the web since 1997

Web browsers: critical security hole in Firefox closed

Summary

In August 2015 attackers exploited a hole in Firefox’s same-origin policy that only affected versions with the built-in PDF viewer. Code distributed via advertising on a Russian website sent local files to a server in Ukraine. It specifically looked for developer files: on Linux, for example, /etc/passwd, SSH configurations and shell histories; on Windows, FTP and Subversion configurations.

Ideas

  • The attack ran in the local file context and could therefore read and upload files.
  • The exploit left no traces on the computer.
  • Mozilla advised changing passwords and keys in the affected files as a precaution.
  • Ad blockers possibly protected users, because the code came via advertising.

Insights

  • Developer and admin computers are particularly rewarding targets because of their credentials.
  • A file viewer built into the browser enlarges the attack surface.

Facts

  • The update appeared as Firefox 39.0.3 and ESR 38.1.1.
  • Macs were not the target of the exploit that was discovered.

References

Critique

  • The report relies solely on Mozilla’s account; how many users were affected remains open.

Recommendations

  • Store SSH keys only with password protection and do not keep credentials in plain text in configuration files.
  • After a possible data leak, change keys and passwords even without proof of misuse.

Read the original article

Search the Web Archive