Arbitrary code execution through unsanitized browser UI
mozilla.org
mozilla.org
Seems to create an iFrame, sets the source to "chrome://global/content/win.xul", then creates a div (with a NS) inside it and sets the content to:
<a onclick="foo()" href="javascript:foo"><script>bar()<\/script>Meh.</a><a href="http://foo/"></a>
The expected results is the div contents is: <a>Meh.</a><a href="http://foo/"></a>What I will say is that Edge and Firefox are doing an excellent job - I'm really impressed. Chrome is still the safest browser today, in my opinion.
Site isolation, which was released recently, is a really great example of how far ahead they are - site isolation is at least 3, maybe 4 years in the making. That's serious work.
They have had an excellent bounty program. They have project 0 doing advanced offensive research, much of which has been relevant to browsers.
They fuzz a ton and have managed to solicit others to do the same (not that other browsers don't/ haven't).
Their sandbox is incredible and constantly evolving. They basically invented seccomp v2 just to improve their sandboxing stature on linux. They implemented 'forceaslr' before EMET was even a thing to help prevent info leaks from third party libs.
Their new kernel32.dll unloading mitigation is awesome, and as far as I know the first instance of such a thing.
I could really go on and on, I'm sure - they have taken incredible proactive measures and they're just getting better at it.
We can see similar growth in Edge, which has had a sandbox for years. Firefox has more recently gotten a sandbox and the move to rust is encouraging.
But... yeah, in my opinion, Chrome takes the cake.
Please don't take it the wrong way, I think Firefox is awesome too :)
What about slashdot-style raw counts of vulnerabilities? As Microsoft got their security more together, it seems like that measure has fallen out of favor.
I am frequently astounded by how many vulnerabilities Firefox point releases address, but I don't know the stats.
A little more fundamentally, vulnerability counts don't provide a great measure of security architecture: whether defense-in-depth and least privilege are good at mitigating the impact of bugs. If, say, you have a JS PNG decoder and once a year someone finds a way for a malicious PNG to run arbitrary JS within the usual web JS sandbox, that's probably way better than having an unsandboxed native-code PNG decoder and once every three years someone finds a way for a malicious PNG to run arbitrary code on the host. (Maybe you can do something involving weighting vulnerabilities by CVSS score or something.)
It's very helpful for counting within a product.
One simple example - A and B are browsers. A has a bounty program that they invest millions into, B does not.
A gets 100 vulnerability reports a month, B gets 5.
Is B safer?
No.
However, let's say we just look at A. It gets 100 a month, and then a new feature is added - suddenly it's 200 a month, and the vulns tend to be in the new codebase. That's interesting information for A - it has nothing to do with B.
I just searched for chrome site isolation and found https://chromeunboxed.com/news/chrome-63-site-isolation-exte.... And from this description the only particularly interesting thing is multiple domains within a single tab get multiple processes, but that doesn't sound all that different from how you get multiple processes per tab if the tab uses browser plugins. What makes this 3 or 4 years in the making?
Also it's disabled by default because of RAM usage.
"The only interesting thing" is a bit disparaging haha that's kind of a big deal. It means that third party iframes, as one example, run in a separate process. It breaks the case where I am evil.com, and you are okta.com, and there is a way for me to leak data within a process (or exploit the process), I can read okta.com's data.
With site isolation is this made considerably more difficult.
If you're concerned about privacy however, then that's a completely different story (that I'm happy to discuss, but probably in another thread).
It sounds like Firefox sometimes injects untrusted HTML into the browser chrome.
https://imgur.com/a/CBftH https://sslanalyzer.comodoca.com/?url=https%3A%2F%2Fadmin.br...
Offtopic: I get the feeling a fair few HN readers don't keep their browsers up to date for whatever reason. It's troubling, seeing as this is a very technical and presumably security-conscious audience.
58 is the fixed version.
>I get the feeling a fair few HN readers don't keep their browsers up to date for whatever reason.
That's because 57 was a complete dumpster fire. It broke all the add ons. Little wonder people would not update. I was a happy FF user for years. My solution was to dump FF and move on, but I know there are still a lot of people clinging to 56/52 like debris from a shipwreck. Anyone who points this out is granted invisibility powers on HN, so I can see how you would be unaware of this.
FTA: This issue did not affect Firefox for Android or Firefox 52 ESR.
> That's because 57 was a complete dumpster fire.
I disagree.
> It broke all the add ons.
Yes, it did. They probably should've made 56 an ESR.
> Anyone who points this out is granted invisibility powers on HN, so I can see how you would be unaware of this.
They must not be doing a very good job, since I've seen the death of long-loved addons mentioned in every Firefox thread on HN for years.
Clinging to 56 is ... well, it's your decision to use what software you want, that's what free software is all about, but since half the point of the changes in 57 was improved security architecture, clinging to 56 and expecting fixes for security bugs seems ill-advised.
Customer controlled environment, where the only browsers are IE 11 and FF ESR, and having Chrome is considered security violation, because their IT cannot control it the same way.
This issue did not affect […] Firefox 52 ESR.
https://www.mozilla.org/en-US/security/advisories/mfsa2018-0...
This bug is fixed in Firefox 58.0.1.