Advisories, PoCs & Exploits
|
|
Unspecified vulnerability in Mozilla Firefox allows remote attackers to spoof SSL/TLS and to steal saved password. Credit to Jordi Chancel
|
|
|
|
1/ When a user is interacting with a window, that window should be visible to the user, to ensure that the user realizes it is there. If a page is displayed in a small enough window, the user may not realize it is being displayed, and if the right keyboard sequence is carefully followed, they can end up performing undesirable actions on that page. Similar attacks could also be used against Opera's preferences to change preferences or select executables to be run by Opera. Additional social engineering steps are needed to ensure that the user presses the correct key sequence, without being able to show any relevant visual feedback, as the page cannot see that the keys are being pressed. 2/
When a user double clicks on a page, they may expect the two clicks to target the same object. If a page uses the first click to open a pop-up window in a predictable location, the second click may focus parts of the new window, such as its address field. If the page can then convince the user to activate a scripted URL seeded in the address field, on a newly loaded target page within the pop-up, it can allow cross site scripting against the target page. Similar attacks could also be used against Opera's preferences to change preferences or select executables to be run by Opera. Non-trivial social engineering would be required to ensure that the user followed the desired sequence of clicks and keypresses, at precisely the right speed, while ignoring the opening and loading of pages within the pop-up.
|
|
|
|
Unspecified vulnerability in Opera allows remote attackers to spoof URL
into the location bar. Credit to Jordi Chancel
|
|
|
|
When the download dialog is displayed, it should always be visible to the user, to ensure that the user realizes it is there. If the dialog is displayed in a small enough window, the user may not realize it is being displayed, and if the right keyboard sequence is carefully followed, they can end up running a downloaded executable. Additional social engineering steps are needed to ensure that the user presses the correct key sequence, without being able to show any relevant visual feedback, as the page cannot see that the keys are being pressed
|
|
|
|
Dialogs such as the download dialog are usually displayed on top of page content, to ensure that the user knows that the dialog is requesting attention. In some cases, this policy was not implemented correctly in Opera, allowing certain page content to overlay the dialog. In these cases, clicking the page content causes the dialog to be clicked instead. While an attacker may not have much control over the appearance of the overlapping content, they may be able to use it to trick the user into performing harmful actions, such as running a downloaded executable
|
|
|
|
The address field should always show the address of the page that is being displayed. In certain cases, if a target site responds slowly, reloading an attacking page and redirecting to the target page can cause the address field to show the target site's address, while the attacking site is still being displayed.
|
|
|
|
Unspecified vulnerability in Google
Chrome allows remote attackers to spoof URL into the location bar. Credit to
Jordi Chancel
|
|
|
|
Unspecified vulnerability in Mozilla Firefox allows remote attackers to cover an addon XPI. Credit to Jordi Chancel
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Critical 
- Vulnérabilité pouvant être utilisée pour prendre le contrôle d'une machine vulnérable à distance. ( Nécessitant peu ou pas d'intéractions de l'utilisateur )
High 
- Spoofing d'un certificat SSL/TLS ciblé. ( Interaction utilisateur commune )
- Accès aux fichiers de l'utilisateur. ( Nécessitant peu ou pas d'intéractions de l'utilisateur )
- Injection de code sur un domaine distant. ( Nécessitant peu ou pas d'intéractions de l'utilisateur )
- Vol des indentifiants de connection enregistrés. ( Nécessitant peu ou pas d'intéractions utilisateur )
- Vulnérabilité pouvant être utilisée pour prendre le contrôle d'une machine vulnérable à distance. ( Avec dificulté dans l'exploitation ou demandant une intéraction utilisateur lourde )
Moderate 
- Spoofing de l'URL dans la barre de location. ( Interaction utilisateur commune )
- Potentiel Cross-Site Scripting.
- Vulnérabilité pouvant avoir un impacte "high". ( Nécessitant une interaction utilisateur non-commune )
- Vulnérabilité pouvant être utilisée pour prendre le contrôle d'une machine vulnérable à distance. ( Nécessitant une configuration non commune du software )
Low 
- Spoofing mineur.
- Bypass d'une sécurité mineur.
- Accès aux informations sur l'historique ou autres informations non-confidentielles.
- Spoofing ( nécessitant une interaction utilisateur lourde ou non-commune. )
- Vulnérabilité pouvant avoir un impacte "Moderate". ( Avec dificulté dans l'exploitation ou demandant une intéraction utilisateur lourde )