Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA)

From: obscure (obscureat_private)
Date: Wed Feb 06 2002 - 17:50:43 PST

  • Next message: lgx: "Re: Encryption Algorithm Footprint"

    Advisory Title: Web Browsers vulnerable to the Extended HTML Form Attack
    Release Date: 06/02/2002
    Effects:
    Internet Explorer 6 and older versions
    Opera 6.0 and older versions
    
    
    Severity:
    Allows stealing of cookies, penetration of internal networks and other evil
    stuff.
    
    Author:
    Obscure^
    [ obscureat_private ]
    
    Vendor Status:
    Internet Explorer - Informed secureat_private and worked with them to
    release a patch. Should be out soon.
    Opera - Worked with the Opera team. A fix is due next release.
    
    
    Web:
    
    http://eyeonsecurity.net/papers/ - Extended HTML Form Attack
    
    
    Background.
    
    Many web browsers such as Internet Explorer allow forms to be submitted to
    non-HTTP services. Some non-HTTP
    services echo back the information sent, and the web browser renders the
    echo as an HTML page, regardless
    of the protocol behind the service.
    
    
    Problem.
    
    A malicious user can create a form which is submitted by the victim
    (automatically using Active Scripting
    or manually using Social Engineering). This form can cause a non-HTTP
    service to echo back JavaScript commands
    which in turn allow the malicious user to steal the cookie for that domain.
    There are more uses for this attack, other than just stealing cookies.
    
    
    Exploit Example.
    
    available at http://eyeonsecurity.net/advisories/showMyCookie.html
    
    
    
    
    Disclaimer.
    
    The information within this document may change without notice. Use of
    this information constitutes acceptance for use in an AS IS
    condition. There are NO warranties with regard to this information.
    In no event shall the author be liable for any consequences whatsoever
    arising out of or in connection with the use or spread of this
    information. Any use of this information lays within the user's
    responsibility.
    
    
    Feedback.
    
    Please send suggestions, updates, and comments to:
    
    Eye on Security
    mail : obscureat_private
    web : http://www.eyeonsecurity.net
    



    This archive was generated by hypermail 2b30 : Wed Feb 06 2002 - 18:40:37 PST