Apple and Google Fix Browser Bug. Microsoft Does Not. (bleepingcomputer.com)
Catalin Cimpanu, reporting for BleepingComputer: Microsoft has declined to patch a security bug Cisco Talos researchers discovered in the Edge browser, claiming the reported issue is by design. Apple and Google patched a similar flaw in Safari (CVE-2017-2419) and Chrome (CVE-2017-5033), respectively. According to Cisco Talos researcher Nicolai Grodum, the vulnerability can be classified as a bypass of the Content Security Policy (CSP), a mechanism that allows website developers to configure HTTP headers and instruct the browsers of people visiting their site what resources (JavaScript, CSS) they can load and from where. The Content Security Policy (CSP) is one of the tools that browsers use to enforce Same-Origin Policy (SOP) inside browsers. Grodum says that he found a way to bypass CSP -- technical details available here -- that will allow an attacker to load malicious JavaScript code on a remote site and carry out intrusive operations such as collecting information from users' cookies, or logging keystrokes inside the page's forms, and others.
Their products are insecure by design.
Because Edge == IE 6 and it is not like Google ever refused to fix a bug while MS did first.
Why am I ever bother writing a reply here?
http://saveie6.com/
An attacker only needs to open a new page via the “_blank” method and use the document.write function to write malicious code inside this page before loading the actual content. The malicious content — the code to execute a banal XSS attack — remains, and helps the attacker bypass CSP protections.
Just choked on my coffee after reading that. What possible use case could there be for allowing a blank page to even run javascript for document.write in the first place?
vos nescitis quicquam, nec cogitatis quia expedit nobis ut unus moriatur homo pro populo et non tota gens pereat.
The attack is to open a blank page in JS, insert your malicious code, then load the victim website. Oh look, your malicious code can run.
MSRC needs a bigger bat to force the IE team to fix this. But they have little influence in the company, which is why logging out of Microsoft websites doesn't invalidate your cookie; you can still use that old cookie to stay logged in. By Design, of course.
technical details available here
Here? Where?
For an internet news site you sure do have a shitty grasp of how the internet works.
systemd is Roko's Basilisk.
Huh, usually it's Apple with the "Broken As Designed stuff, I guess Microsoft is playing catch up in that area too ;)
Violence is the last refuge of the incompetent. Polar Scope Align for iOS
It's only Edge, so hardly anyone will be affected.
windows 10 S you fail again just wait for EU smack down.
iOS is locked to WebKit
If you don't use the latest macOS version, you can't upgrade to the latest version of Safari.
#DeleteFacebook
Where did the browser option "load only from origin site" go?
Edge is suppose to be NEW browser but from the mozilla/firefox page it is one of those none standard IE "features". https://developer.mozilla.org/...
TL:DR
If your site is already outputting the necessary CSP headers and sanitising it's HTML correctly, I find it hard that you'll get your malicious JS payload to even invoke let alone open up a new blank page. Just sayin'.
If the attacker is already able to run JS from your page then you have other issues.
If they want us to believe they aren't in cahoots with the NSA they should patch anything that vaguely smells of NSA.
No kidding. "Brevity is the soul of wit."
Lol gn from outer space is a funny movie.
At least update the irc servers you are putting in this. Those two servers, irc.secsup.org and irc.easynews.com haven't existed on EFnet in probably over a decade...
sure, this time the people at NSA and CIA gave a court order to the sorry people at Microsoft, and they weren't allowed to fix the bug, but there are a dozen of these hiding in the other browsers, kept there by the same kind of court orders.
If it's American, then it's back-doored by design. That's what you need to start telling people.
Annoys the heck out of me. Came across this on Edge and I was floored that hobo.homeless.com got access to all of homeless.com's cookies. I had to put in a few lines in my cookie saver/getters that append "hobo" to the front automatically based on URL.
Those are of course made-up names.
This is an integral part of windows telemetry
You use data like a drunk uses a lamp post: for support, rather than illumination.
I'm sure you've been waiting for an opportunity to shoehorn that little inspirational nugget in one of your comments. Unfortunately, it doesn't work as well as you would have hoped because
1) it sounds as corny as the text in a discount Hallmark Get Well Soon card
and
2) I didn't "use data", I merely copy-pasted stuff from the first result that comes up when one googles "top 10 cve", which even by your self-righteous, biased standards can hardly be construed as being dishonest
I don't want to prevent you from living in that tinfoil hat fantasy land where every piece of information you see that doesn't support your preconceived ideas must be planted by some "shill" (if such thing even existed for real on Slashdot). The world is a beautiful mosaic and irrational angry tools like you are part of it. Just try to avoid leaking your Pinterest material in your Slashdot comments and everything will be fine.
lucm, indeed.
I'm sure you've been waiting for an opportunity to shoehorn that little inspirational nugget in one of your comments.
I rarely have to wait for very long before some hapless turd wanting to score snarkpoints on [_fill_in_discussion_forum_here_] ambles along and demonstrates a piss-poor understanding of what facts are and what they mean. I've used the term many times before.
Unfortunately, it doesn't work as well as you would have hoped because [meaningless argle-bargle]
Get over yourself. It was a direct hit. The only one here who maybe doesn't understand that is you.
2) I didn't "use data", I merely copy-pasted stuff from the first result that comes up when one googles "top 10 cve"
A meaningless distinction if ever there was one.
As others have noted, Windows is largely split across multiple versions, while virtually nothing else is. To willfully ignore that is to willfully misuse the facts in your pursuit of snarkpoints. And for that, you suck, oh-ohhhh!
People who say "sheeple" have about as much sophistication as an AOL user, and in fact are probably actually AOL users.