Hackers claim $10,000 prize for breaking into StrongWebmail
thestandard.com
thestandard.com
http://www2.telesign.com/login.php?loginerror=yes&user=\...
Pathetic. (Telesign is behind StrongWebmail)
I verified that the latest version of Chrome and Firefox doesn't prevent the XSS attack.
That could be done with an XSS attack using JavaScript to access the cookie and divert it.
I considered doing this but would have needed to sign up for an account and that required giving a credit card which I didn't want to do. Well done to the people who made it work.
Strike that, reverse it.
The IDG attack did not work initially, but succeeded when security software called NoScript was disabled on the Firefox browser, running on a Windows XP machine.
Oh my.
IDG probably logged in with NoScript enabled, preventing the attacker's script from being run by IDG's browser. Disabling NoScript allowed the CSRF attack to work properly. The website was merely an unwitting pawn.
They used XSS (cross site scripting) to send a mail to the target. When the email is viewed a CSRF (cross site request forgery) is executed to add a new device (phone) to the authenticated devices list. Next they log in, receive the SMS on their phone that is now in the list...bam!
[Edit: I didn't mean XSS to send the email, I meant inject an XSS attack into the email and send it. I'm thinking something like psuedo: location.replace(/link/to/add/device/?phone=555-1212 ]
They probably sent the mail like you said, only used the CSRF to jack the cookie, which would be easier than adding a phone to the list.
Victim logs in using two-factor auth, gets a cookie which lets them back in without phone in future.
Attacker sends email to victim with some kind of script embedded.
Victim views email, javascript runs and sends cookie info to attacker.
Attacker uses cookie to impersonate victim.
Of course, it's been a long day here too, and I'm so far from an expert on this stuff it's entirely probable that what I just described doesn't make sense/isn't possible.
Edit: Yeah, guess what I described is more XSS than CSRF
That said they say they also needed a strongwebmail account for it to work so I could be wrong - perhaps they just hijacked their authed session ID into the ceo's (possibly??)
"alternatively- add a device to the auth list and wala ;)"
[edit: I should note that XSSExploits seems to be the twitter account for the company that won the contest)
In fact I recently received a four inch thick stack of documentation, APIs, etc... via FedEx from a bank because they didn't trust my e-mail and I wasn't on "the list" for their "secure e-mail" site (pay per account thing).
So yes, reasonable or not, secure or not, there is a business supplying "secure" communications for businesses.
This? this is straight up public humiliation.
When the CEO (or anyone else) would receive the alerts that someone was trying to break into their accounts, the XSS or javascript (or whatever) would be included in the alert and executed ... That's probably how they broke into it and why it didn't work with noscript enabled.
Even if they fix this, I wouldn't trust a company that claims their product is very secure, offers a $10k reward for hacking it, then gets exploited in less than a day by (most likely) the simple XSS vulnerability mentioned in another comment.
No, weegee is referring to this story which was deleted as spam apparently: