Why does Google prepend while(1); to their JSON responses?
stackoverflow.com
stackoverflow.com
Also note that this attack, JSON Hijacking, is different than a CSRF (Cross Site Request Forgery) and has little to do with CSRF tokens.
Actually, it's not security measures so much as implementing ECMAScript 5, which explicitly says that array literals must use the built-in constructor, not any override. See 11.1.4 [1], which reads:
> Let array be the result of creating a new object as if by the expression new Array() where Array is the standard built-in constructor with that name.
Object works similarly, and is in 11.1.5. I'm not certain what earlier standards said here, but I suspect they didn't say anything.
[1]: http://www.ecma-international.org/publications/files/ECMA-ST...
with the status "unable to contact the vendor or actively neglected by the vendor" :-/
Edit: I meant "injecting" not inlining. Thanks chc for pointing that out.
https://news.ycombinator.com/item?id=5168121
(from about a year ago)
<script type="text/javascript">
Object.prototype.__defineSetter__('Id', function(obj){alert(obj);});
</script>
<script src="http://example.com/Home/AdminBalances">/*Boom*/</script>
[0]: http://haacked.com/archive/2009/06/25/json-hijacking.aspx/Example http://jsfiddle.net/V53BL
<script>
Object.prototype.__defineSetter__('user', function(obj){alert('Hijacked!');console.log('Hijacked!', obj)});
var trigger = [{"user":{}}];
</script>
<script id='current-user' src="http://my.secretapi.com/users/current"></script>
Where the API returns something like [{'user':{'name':'Joe Bloggs'}}]
(Un)Fortunately (depending on which side of this you're on...) they've plugged the holes?var x = [{"user":"dude"}]; This won't trigger, and this is what the script include tag executes via the response.
x.user = "wow"; This will trigger, however.
However, the while (1); (or similar tricks) is an easy defense-in-depth measure in case browsers regress in this area or new attacks are found.
The idea: you need such workaround only if you return JSON Array.
Most of the API returns JSON Object in which case the attack does not work, it will result in syntax error.
http://docs.angularjs.org/api/ng.$http#description_security-...
[1]: https://github.com/jcoglan/unsafe_sjr/blob/master/README.md
(I've just tested Firefox network view and it breaks the response display with syntax error -- there should be an option to select the format).
while(1) is ugly solution to currently non-existing problem.
Of course, anyone can code their own browser to lie about headers. It doesn't make much sense to specifically open yourself to vulnerabilities though.
There's downside, though - you can't inspect JSONs by simply opening them in a new tab.
This only prevents attacks that uses a script to execute a get method and returns a JSON array.
JSON arrays can be "executed" as if it was javascript. The attack relies on modifying what javascipt does when this faux script is ran.
So if you put a "while(1);" in there, it prevents it from finishing. Thus preventing the exposure of the sensitive data.
It's similar to CSRF since that attack relies on the user to have an active session to be able to access sensitive data, but they differ in MO.