Social

Firefox: HTTPS and response code 407

Today's release of Firefox 19.0 fixes an interesting bug that I reported to the vendor back in October 2012. In essence, an attacker on an untrusted network could first coerce the browser to use a rogue HTTP proxy (this can be done by leveraging the WPAD protocol); wait until the browser attempts to download a HTTPS document from an interesting site through said proxy; and then selectively respond to the appropriate CONNECT request with a plain-text message such as this:

<br />HTTP/1.0 407 Boink<br />Proxy-Authenticate: basic<br />Connection: close<br />Content-Type: text/html<br /><br /><html><br /><h1>Hi, mom!</h1><br /><script>alert(location.href)</script><br /><br />[...additional padding follows...]<br />

The browser would show the user a cryptic authentication prompt - but hitting ESC or pressing cancel would inevitably result in the proxy-supplied plain-text document being rendered in the same-origin context of the requested HTTPS site. There goes the transport security - so I guess that's an oops?:-)

Related Posts:

  • Inflation and unemploymentThe FOMC decided on March 21 to increase the target band for the federal funds rate by 25 basis points, to a range of 1.50-1.75%. This despite inflati… Read More
  • What anchors inflation?Conventional wisdom is that a central bank can anchor the long-run rate of inflation to a target of its own choosing. This belief is evident where eve… Read More
  • Inflation and Unemployment (Part 2)In my previous post (Inflation and Unemployment), I reviewed what I thought was a fair characterization of the way the Federal Reserve Board staff org… Read More
  • Den irrasjonelle presidentenAsle Toje mener i DN 3. mars at Donal Trumps straffetoll på stål er rasjonell. Toje nevner at tollen kan stimulere økonomien, bidra til et infrastrukt… Read More
  • Hjemmelaget indeks gav kjempegevinstOljefondet har konstruert en hjemmelaget indeks som visker ut tapene fra departementets mislykkede faktorstrategi.Det er ikke noen faglig uenighet om … Read More

0 nhận xét:

Đăng nhận xét