> One of the recent additions to the CSS language was a feature that would allow it to load and run JavaScript code from within a CSS rule.
What in the actual fuck?!?
Then, looking at the actual code:
<script type="text/javascript" xml="space">// <![CDATA[
new Function(getComputedStyle(document.documentElement)?.getPropertyValue('--script'))();
...
Okay, just accessing some random CSS variable from a script tag.I wish tech journalists could ask someone with technical knowledge to double check before parroting hyped BS like this.
If the article ever had the quote you included, it appears to have been removed and replaced with a fairly thorough explanation of what’s actually happening. (Perhaps the link has been changed?)
Just to be clear, this would’ve worked decades ago. There’s no inherent need to use CSS3 variables for this. It could’ve just as easily been hidden in a normal property.
https://www.zdnet.com/article/unsecured-mongodb-databases-ex...
You’d think that basic critical thinking would keep anyone from putting their name on this story.
> why would you eval() CSS?
It’s really as simple as “because you can”. This is just an obfuscation technique.
So, the hackers need to have access both to CSS and HTML to put the malicious JS that looks innocent in the HTML and load the malicious JS from the CSS.
Now it makes sense, thanks.
It may have access to the window object, however, so if something important is there, if can probably mess with that.
> Is this some pattern with a popular JS framework?
I've never seen this anywhere before, JS grabbing values from CSS, but I mostly done ClojureScript development for the last 2 years.
Older browsers used to have lots of ways to execute js from css (e.g. expression()) but all the browser vendors realized that that was terrible and are careful not to allow it. Most modern pure css attacks (in general, not what this article is about) involve loading different background images based on page content to exfiltrate secrets.