I know your name, where you work, and live (Safari v4 & v5)
jeremiahgrossman.blogspot.com
jeremiahgrossman.blogspot.com
Short summary: Safari autocompletes forms from your private address book, and can be tricked into doing that by Javascript events on form fields named in ways Safari would want to autocomplete; worse, once autocompleted, that data can be read out of the form by the same JS that triggered the event.
Long story short, if you browse to a site with Safari and you have autocomplete on, that site can slurp some stuff out of your address book.
that site can slurp some stuff out of your address book.
More specifically, it can slurp some stuff from your personal address card that you've set in AddressBook.app
This hack does not allow you to get the address of someone's mother-in-law.Unless you're the mother-in-law :).
They do not use your system's address book to fill forms online.
The most important distinction though, is that you have to still select to fill that out manually.
Of course logins are another story - those are automatically filled in. But those are restricted to the page you already entered them on, and you have to decide you want that information filled explicitly.
Steps:
1. Go to a popular site that makes one fill out the information you want to steal.
2. Record the name they use for all their fields (afaik this is how FF determines what value to supply)
3. Use the hack to make a form with those fields
4. Profit
On step 3, it may be that you have to enter the field and type something to get the auto-complete to kick in, but that's easy: you only need to try 26 letters and 10 numbers to get a hit.
Step 1 and 2 aren't required - the field names are 'standard'.
Step 3 is what the test page does already.
Edit: It looks like the javascript used to generate keypresses isn't supported by Firefox:
https://developer.mozilla.org/en/DOM/document.createEvent
var event = document.createEvent('TextEvent');
event.initTextEvent('textInput', true, true, null, char);
input.value = "";
input.selectionStart = 0;
input.selectionEnd = 0;
input.focus();
input.dispatchEvent(event);I havent used the autofill feature (have never trusted it), but in Chrome apparently it is site-specific, and requires user intervention for it to work. I'd be interested in how FF handles it.
The second I can't test, but looking at the screenshot, it appears that Safari actually fills in the text field with the contents of the auto-fill, before you actually choose that auto-fill, and it highlights that text so typing something overwrites it, which is a standard way of doing autofill. However, using script to ask the textbox for its contents then exposes sensitive data. In contrast, other browsers display the sensitive data in (inaccessible to script) browser chrome, so no data is exposed.
Safari: R|*obin Message* (in the textbox itself)
Firefox: R|
Robin Message (in a popup, push down to get to it)Details here: http://www.advogato.org/person/mbrubeck/diary/92.html
> I figured Apple might appreciate a vulnerability disclosure prior to public discussion, which I did on June 17, 2010 complete with technical detail. A gleeful auto-response came shortly after, to which I replied asking if Apple was already aware of the issue. I received no response after that, human or robot.
I suspect that Apple doesn't have a lot of goodwill in the security community these days. For better or worse, they're viewed as indifferent on the subject of security.
And really, I don't think it's that unreasonable to expect a fail proof level of response on security vulnerabilities from the world's most valuable computer company.
Your expectations are unrealistic.
The biggest problem this whole industry has right now is that it is excruciatingly hard to find talent. Nobody has enough people. Everyone, from Google through MSFT through Adobe though Apple through Cisco &c &c &c, is screwing things up because of it.
Wait, what? You think it's unrealistic to expect every security-related bug filed to get some kind of a human follow up within 30+ days?? And this from a company that made over one BILLION in profit during that same time frame?
Uh, no.
"Hello this x, with Apple's Product Security team. We've received your report and have assigned it #123456. We will begin investigating soon. Thanks"
And you should probably be more careful in what you wish for because I actually have reported security vulnerabilities to Apple before. And in one case, I waited even longer than a month for a reply (rdar://3775607).
Did you still have a point to make?
I don't know how or what you reported or what channel you used to report it. It's possible that Apple makes this reporting process overly confusing. But I simply don't buy that other large vendors are significantly better at reporting progress than Apple. The MSRC takes flak all the time for how they handle reports, Adobe gets more flak than even Apple does, and I think your expectations are unrealistic.
In all cases, the process is, report bug, get pro-forma response, wait forever. Hence NMFB, hence "rebooting responsible disclosure".
If you reported a obviously bad flaw to Apple using product-security@, and they never fixed it or fixed it without crediting you on the credits page they've maintained for something like 5 years now, I apologize for making the assumption that someone saying the things you're saying has never reported a security vulnerability to Apple.
Let me try to clear up my point of frustration with the whole untimely response thing.
A quick search reveals that MSRC (which you cited) receives something like 300 emails a day. I could easily be wrong, but let's assume Apple's volume is close to this number as well.
So that's 300 divided by 8 hours a day or about 40 messages an hour. Using my earlier example of a human simply replying with his/her name/contact, and a tracking number, we'll be generous and say it takes a half hour to do this, that's 16 messages processed by a single tier-1 security support staff in one day.
If we now divide 40/received/hour by 16/processed/day we get that APS would need to add roughly 18 additional team members to handle a reporting volume equal to that of Microsoft.
Not from the valley, but it looks like tech support make around $50K a year out there, which we would multiply by the additional staff for: $50k * 18 = $900,000/year.
According to the conference call this week, Apple makes over $32,000,000 in _profit per day_.
Essentially, if Apple wanted to greatly improve their image and contact with outside researchers, they could take 0.03% of a single day's profit, and provide every person that submits a bug a with an immediate human contact and tracking number.
Hell if even if float these numbers up by several magnitudes, does it really sound like too much to ask?
edit: mathfail, but bottom line is still valid /done ;)
And, like I said, I think they're significantly better at responding to reports than the picture you're painting. We may be talking past each other, but: having an actual human write back and say "thanks, you're secrdar://484799" might not actually make things any better than they already are.
The fact is that large companies haven't figured out how to ship security fixes, and so security fixes are ending up getting triaged alongside all other classes of product flaws. And that isn't working.
Sorry, maybe a stupid question, but can someone explain this? I had no idea my OS had an address book. Why does it have this? If it does, how do I put stuff in it? Or delete stuff in it? Is this just on mac, or windows and linux too?
I also see an idiot commenting about his mother in law, sadly theses people never understand concerns for privacy.
I also see an idiot commenting about his mother in law, sadly theses people never understand concerns for privacy since being apple fanboi they already have hardly anything to hide.