Dynamics of Google, Apple and Microsoft when the browser has a security error
While Apple and Google urgently sought to patch security holes in Safari (CVE-2017-2419) and Chrome (CVE-2017-5033) browsers, Microsoft did not notice. This security vulnerability was discovered by Cisco Talos researchers in Safari, Chrome, and Edge browsers, but Microsoft believes that this security is due to design.
According to researcher Nicolai Grødum at Cisco Talos, this vulnerability is classified as a exit from CSP (Content Security Policy) - a mechanism that allows web developers to configure HTTP headers and instruct users to access Source browser (JavaScript, CSS). Content security policy (CSP) is one of the tools that browsers use to implement SOP - Same-Origin Policy within the browser.
Grødum said he found out how an attacker who bypassed CSP, downloaded malicious JavaScript code on a remote site and performed intrusion operations such as collecting information from the user's cookie or recording the syntax press key in page structure, .
Exploiting vulnerabilities is quite simple
Exploiting this vulnerability in the browser is quite simple - at least for those with a background in web development. An attacker just needs to open a new website via the '_blank' method and use the document.write function to write malicious code inside this page before downloading the actual content. Malicious content (also known as initial XSS attack code) remains and helps attackers overcome CSP protection.
Grødum found the vulnerability in November last year. This issue is ranked seriousness CVSS is 4.3 / 10.
Users of the Edge browser are easily vulnerable to this vulnerability while Google Chrome users 57.0.2987.98, iOS 10.3, and Safari 10.1 or newer are all protected. And Firefox is lucky to be unaffected.
You should read it
- Vulnerabilities discovered in many web browsers that allow users to be tracked through installed applications
- Find security holes on every site with Nikto
- Protect your Web browser
- The unsafe 'feature' on UC Browser allows hackers to take control of Android phones remotely
- IBM developed a new technology to patch security holes
- Microsoft introduced a tool to fix security holes in IE 9 and 10
- 5 common errors in managing security vulnerabilities
- HP publishes a series of critical vulnerabilities in the Teradici PCoIP protocol
May be interested
- Featured technology products at IFA 2017as one of the most important technology events with tech followers, ifa presents a variety of products, from computers, phones to memory cards, headsets ... here are some outstanding products at ifa 2017 in berlin.
- Visual Studio Code now has an extremely useful color pickerthe cross-platform code editor of the new microsoft visual studio code adds extremely useful features in the latest update.
- Photoshop's new Pen Tool makes it easier to draw curvesif you've ever worked with photoshop, you'll probably find it difficult to draw or select curves (curved path). now adobe has come up with a better solution in the photoshop update.
- Twitter's Night Mode night mode launches desktop userstoday twitter launched night mode for users of the web version on the computer. this information has been confirmed by twitter spokespersons when they started testing last month and are now officially released.
- Google Drive closed, replaced with Backup and Syncgoogle's online repository - google drive and google photos - is preparing to say goodbye.
- Google's new Dashboard makes it easy to find collected Google information from usersgoogle makes it easy for you to find out what information the company knows about you thanks to a new update on the control panel of activities related to google.