HNHacker News
TopNewBestAskShowJobs

kdarutkin

41 karma · joined March 23, 2021

submissionscomments
kdarutkin··on Open source website bundle analyzer that shows vulnerable NPM packages
I’d like to share an open source project I’ve been working on during the last year. It analyzes production JavaScript code and detects bundled NPM package versions. A vulnerability is shown when a specific detected version contains known vulnerabilities, taken from the Github advisory.

There’s also a dedicated package page, that shows accumulated statistics of a package. It’s like wappalyzer or builtwith but with better accuracy. For example: https://gradejs.com/package/react

So far I’ve only indexed ~10,000 popular websites. The current version works for Webpack bundles with 70-90% accuracy and ~3% false positive. The package detection algorithm is designed to match minified and tree-shaken AST subtrees for each export per bundled JS module.

I'd like to collect any feedback from the community.

Repository: https://github.com/gradejs/gradejs

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
It is possible on Tor Browser. Chrome and Firefox show a confirmation popup in the main frame.
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Wow, that's weird.

The internet connection may be the issue here, or the custom configuration on Safari.

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Thanks for the feedback. The accuracy is the main issue on Chrome. See also https://news.ycombinator.com/item?id=27147876
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
We haven't tested Vivaldi so far and the demo is not designed for it. However that doesn't mean Vivaldi is secure against this attack.
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
This is possible in theory.

For example, Safari opens the Apple Music without any user prompt. The app itself is designed to handle deep links (such as opening an album or starting the song).

That means you can perform a deep link forgery, in order to force the app to perform unwilling action without user confirmation.

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
We will make a detailed report with some statistics, after the vulnerability is fixed
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Mostly because it took hours to make an exploit on Safari compared to days on Firefox, however the final approach ended up the same. Only Chromium has a built-in scheme anti-flooding protection.
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Edge 90 is also affected. We tested it on Windows 10.
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Thanks.

Linux is tricky. Mostly because Chrome opens applications through `xdg-open`. Custom configuration on Firefox may also affect the result.

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
I also made a special branch for Chromium (Chrome, Brave, Edge, etc.) that works much slower, but should be more accurate.

It still may not work for your browser with a custom configuration. Also, it is better not to make any gestures during the process.

https://github.com/fingerprintjs/external-protocol-flooding/...

https://609d9f4d79c4f6000700782c--boring-visvesvaraya-dbefd4...

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
I’m the author.

The accuracy can be low because of:

- Custom browser settings or flags - The demo was designed for the default setup, but that doesn’t mean your custom setup is not vulnerable.

- Poorly performant hardware (including virtual machines) - Some timings are just hardcoded and were tested on the MacBook hardware.

- Fullscreen mode - The demo will work faster and more accurate if the browser is not in a fullscreen mode

- Slow internet connection

- Gestures during the process

Also, we haven’t looked into Opera yet, but we may if you ask to do it.

For the technical questions or bug reports consider using Github Issues

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Hi, agilob. I've updated the demo for Chromium and made it work slower, in order to increase accuracy. See also https://news.ycombinator.com/item?id=27147325
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Chromium results may be flaky on slow internet or because of less performant hardware (such as Virtual Machines).

I've updated the demo for Chromium and made it work slower, in order to increase accuracy.

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
The exploit was tested in Safari 14.0.3 and 14.1 on MacBook M1 and MacBook Pro. What version do you have?
kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Any custom settings may affect the result. However default settings will work for the Firefox 88.0.1. Was tested on Windows, Safari and Linux.

Chrome does not work on Ubuntu, since it opens everything with xdg-open and creates confirmation dialog for both installed and not-installed application

kdarutkin··on Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
Hi, nimbius.

I’m the article author, can you please clarify your question?

The demo will not work without a popup window in Chrome, Firefox and Safari. The “Get My Identifier” button is needed in order to have a single user gesture to open an additional window.

However the Tor Browser demo works silently without any additional window.