|
|
|
AniWeather Add-on Configuration Vulnerability |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : AniWeather is a very popular add-on for both Mozilla Firefox and Google's Chrome. While looking at its configuration page one day, I realized that there wasn't much protecting AniWeather's configuration. To configure AniWeather, it uses this page hosted at the AniWeather website. I copied the page and ran it as a local file it worked the same Just keep it the same filename - aniweather.config2.html. AniWeather was just checking if the filename was the same, allowing anyone to host the file that does configuration, possibly with other intentions.. such as onload configuration changes to take effect when a target user visits the webpage, etc. Not a huge vulnerability, but configuration files should be protected at all times, especially from untrusted remote hosts. Kudos to the team at AniWeather, they provided a decent fix that checks the hostname and makes sure the configuration page that interacts with the add-on comes from the trusted source. Just watch out for DNS attacks now.. heh. Thanks for reporting the vulnerability. I have upgraded the add-on and forced the host name checking. AniWeather uses a configuration page mainly to be compatible w Google Chrome browser so that both browsers share identical experience. Since these days updating add-ons in mozilla.org takes forever, you can get the latest version 0.6.9 directly from www.aniweather.com. In fact, if you are a US user, you can also enjoy a rich set of graphic reports including hi-res radar in the new version. Let me know if you have any further questions or comments. Thanks again and have a nice day It actually took them less than 2 hours to respond and upgrade AniWeather... now if other vendors could be so efficient
Les mots clés de la revue de presse pour cet article : add-on vulnerability Les videos sur SecuObs pour les mots clés : vulnerability Les éléments de la revue Twitter pour les mots clé : vulnerability
Les derniers articles du site "Jeremy's Computer Security Blog" :
- What did they fix - Adobe Flash Temporary Filename Scheme - Reverse Engineering File Formats - Browser Fuzzer 3 - Writing Code that Breaks Code - Mozilla Code sighs - From Static Analysis to 0day Exploit - Some vendors are 'unconcerned' - Firefox Local Download Manager Vulnerability - Desktop Management Interface DMI
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|