Login Register


17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device filter_list
Author
Message
17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device #1
[Image: https%3A%2F%2Fblogs-images.forbes.com%2F...00x448.jpg]

17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device
Except for phishing and scams, downloading an HTML attachment and opening it locally on your browser was never considered as a severe threat until a security researcher today demonstrated a technique that could allow attackers to steal files stored on a victim's computer. Barak Tawily, an application security researcher, shared his findings, wherein he successfully developed a new proof-of-concept attack against the latest version of Firefox by leveraging a 17-year-old known issue in the browser.
Tawily told The Hacker News that Firefox is the only major browser that didn't change its insecure implementation of Same Origin Policy (SOP) for File URI Scheme over time and also supports Fetch API over file protocol.

Demo: Firefox Local Files Theft (Unpatched)



Firefox is not going to patch it anytime soon
The researcher responsibly reported his new findings to Mozilla, who responded by saying "Our implementation of the Same Origin Policy allows every file:// URL to get access to files in the same folder and subfolders."
This suggests that the company currently seems to have no plans to fix this issue in its browser anytime soon.
In 2015, researchers discovered a similar, but remotely executable, vulnerability in the same-origin policy for FireFox that attackers exploited in the wild to steal files stored on Firefox users' computers when they clicked malicious ads on websites.


Looks like I won't be going to Firefox anytime soon even though the browser customization in terms of privacy is far superior than any browser out there now.

Source: https://thehackernews.com/2019/07/firefo...cking.html


Ransomware is more about manipulating vulnerabilities in human psychology than the adversary’s technological sophistication.

[+] 1 user Likes Tracefl0w's post
Reply

RE: 17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device #2
Hmm, I never knew this was a problem on Firefox. I already switch between Chrome and Firefox often since I get better performance with Chrome. The Firefox developers usually make security and the user their top priority.
â €
[Image: KmPTi6b.png]

[+] 1 user Likes Drako's post
Reply

RE: 17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device #3
It's taken them this long to Identify It, and now they're not willing to take Immediate action.

Not good from a developer's standpoint.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: 17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device #4
(07-05-2019, 03:39 AM)Drako Wrote: Hmm, I never knew this was a problem on Firefox. I already switch between Chrome and Firefox often since I get better performance with Chrome. The Firefox developers usually make security and the user their top priority.
That's what took me by surprise aswell, the least I expected was that the dev team would patch the exploit.


Ransomware is more about manipulating vulnerabilities in human psychology than the adversary’s technological sophistication.

[+] 1 user Likes Tracefl0w's post
Reply

RE: 17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device #5
(07-05-2019, 04:18 AM)mothered Wrote: It's taken them this long to Identify It, and now they're not willing to take Immediate action.

Not good from a developer's standpoint.
That's certainly not good from a developer's standpoint. However the team might see it more as a loophole than a exploit.


Ransomware is more about manipulating vulnerabilities in human psychology than the adversary’s technological sophistication.

[+] 1 user Likes Tracefl0w's post
Reply

RE: 17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device #6
(07-05-2019, 09:27 AM)Tracefl0w Wrote:
(07-05-2019, 04:18 AM)mothered Wrote: It's taken them this long to Identify It, and now they're not willing to take Immediate action.

Not good from a developer's standpoint.
However the team might see it more as a loophole than a exploit.

That's the alarming part- a loophole ls a gateway for an exploitation.
[Image: AD83g1A.png]

[+] 2 users Like mothered's post
Reply







Users browsing this thread: 1 Guest(s)