Login Register


LastPass Vulnerable to Extremely Simple Phishing Attack filter_list
Author
Message
LastPass Vulnerable to Extremely Simple Phishing Attack #1
Quote:Security researcher Sean Cassidy has developed a fairly trivial attack on the LastPass password management service that allows attackers an easy method for collecting the victim's master password.

Mr. Cassidy discovered that whenever LastPass sessions expire while the user is browsing the Web, LastPass shows this using notifications injected in a page's content. The subsequent login page and the two-factor authentication code, if enabled, are also displayed in the same way.

In terms of security, this is a big no-no, since it exposes users to Web injection attacks, commonly found in phishing attacks against users of Web-based banking portals.

Following an initial hunch, Mr. Cassidy explored this apparent weakness and discovered that attackers can exploit LastPass' tendency to show notifications and login popups inside a live Web page.

The researcher open-sourced the tool that carries out this attack

Mr. Cassidy developed a tool, which he also published on GitHub, called LostPass, which would be able to automate a simple phishing attack against LastPass users and harvest their password vault.

According to Mr. Cassidy, the only thing attackers need to do is to reroute users to a legitimate website that's vulnerable to XSS (cross-site scripting) attacks.

On these legitimate, yet vulnerable websites, the LostPass tool will use the XSS flaw to detect if a user has LastPass installed on his computer, log him out using a known CSRF issue, and then insert a notification asking the user to log into his account once again.

When the user clicks on this notification, a pixel-perfect LastPass login page appears, and when the user enters his credentials, they'll be logged on the attacker's server.

Attacker can intercept 2FA codes

Additionally, the attacker can even check these credentials against the LastPass API, verify their accuracy, and even ask the user for the two-factor authentication code if this feature is turned on.

If everything is correct, and all the codes verify through, using the same LastPass API, an attacker can collect any data from the user's account he wants, including the password vault.

Mr. Cassidy says that LostPass works only with Chrome browsers, since Firefox and other browsers show the LastPass login screens via browser specific popups. Cassidy says that he's working on experimental support for Firefox. LostPass was also tested with LastPass' most recent version, the 4.x series.

LastPass was notified but did not address the issue properly

The security researcher contacted LastPass last November. The company said they "confirm this is a phishing attack, not a vulnerability in LastPass." The company tried to fix this issue by warning users when they type in their master password into a website, but Cassidy said this was pointless since the warning was also a Web injection and can be intercepted and disabled by the attackers.

For now, this attack is also made easier in Chrome by the fact that attackers can register domains like "chrome-extensions.pw" that resemble the Chrome extensions management section, all without being warned by the browser.

In Firefox, Mr. Cassidy is working on a method that draws the OS-specific popups inside a page using HTML and CSS, making the user think he's entering the data into a LastPass window, when the data is actually entered inside the Web page.

Some mitigation techniques

To mitigate against his own attack, Mr. Cassidy recommends that users never re-enter LastPass credentials inside the browser, and use the main application to authenticate again.

Additionally, he also says that turning on IP restrictions for the LastPass paid version is better than using 2FA protection. Furthermore, users should also disable mobile logins, and log all logins and login failures.

Source: SoftPedia News
[Image: CDUAq9d.png]

[+] 1 user Likes Shebang's post
Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #2
Honestly, I think it's just a bad idea to use a password manager in general. Even having them saved locally on a browser puts me off a little. Maybe i'm just paranoid.

Good share.

Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #3
didn't last pass get hacked last year?
Whoop Whoop?

Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #4
(01-19-2016, 09:39 PM)ImmNinjaxD (⌐■_■) Wrote: Honestly, I think it's just a bad idea to use a password manager in general. Even having them saved locally on a browser puts me off a little. Maybe i'm just paranoid.

Good share.

Yeah, I've always considered password savers a big no no. Storing passwords in any form on your system is just stupid.
[Image: qcYJ3l.png]

[+] 1 user Likes Skullmeat's post
Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #5
(01-20-2016, 08:54 AM)Skullmeat Wrote: Storing passwords in any form on your system is just stupid

Absolutely agree.

Even on encrypted drives, although It's pretty secure, I don't store any critical credentials. I use the good ol' pen & paper and keep the booklet In a secure place at home. On topic here, I've never been a fan of Password Managers and this thread proves why.
[Image: AD83g1A.png]

Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #6
I use a password manager, sure it's terribly unsafe to keep your passwords logged - but the pain of remembering all the variations of passwords is way too much of a hassle. I don't save/store any of my financial passwords like online banking details because I'm super paranoid about those, but all my other accounts are stored.

Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #7
(01-23-2016, 12:03 PM)Skullmate Wrote: but the pain of remembering all the variations of passwords is way too much of a hassle.

Honestly, I use the same three passwords for everything. Not the safest thing to do, but if I forget my password i'll just try all 3 to see which one I was feeling that day.
I suppose, though, if someone really wanted to hack you, not having a storage service would just make it a tad harder at the most.

Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #8
I use Keeper. The only one i really trust. The company can not even see your information been using it for the past 3 years. https://keepersecurity.com/

Reply

RE: LastPass Vulnerable to Extremely Simple Phishing Attack #9
(01-23-2016, 03:00 PM)ImmNinjaxD (⌐■_■) Wrote: I suppose, though, if someone really wanted to hack you, not having a storage service would just make it a tad harder at the most.

Having a strong password Is only one factor In securing your account.

The password recovery options on any given account, Is the weakest and most vulnerable point of access to "reset" the password. For Instance, Google accounts (for example, Gmail) use 6 digit verification codes to reset the password on the account when selecting the "Phone Text/SMS" option during the account recovery process.

Anyone. from any device and any location can generate the code to the cell phone of the rightful account holder. The verification code reads "Your Google verification code Is 760992", which does not denote It's objective. Those who have never accessed the recovery options and performed a recovery on their account, wouldn't have a clue as to "why" they've received the code. As a result, It's very easy to SE your victim for the code, and reset the password on the account without any other form of authentication.
[Image: AD83g1A.png]

Reply







Users browsing this thread: