BugTraq
BackToFramedJpu - a successor of BackToJpu attack Nov 25 2003 09:56AM
Liu Die Yu (liudieyuinchina yahoo com cn)


BackToFramedJpu - a successor of BackToJpu attack

[tested]

OS:Win2k3,CN version

IE: with MS03-048 installed.

OS:WinXp, CN version

Microsoft Internet Explorer v6.Sp1; up-to-date on 2003/11/16

[overview]

A cross-zone scripting vulnerability has been found in Internet Explorer. If a webpage contains some subframe(either FRAME tag or IFRAME tag), its security zone may be compromised.

[demo]

There is a harmless demo:

http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu/BackToFramedJpu-
MyPage.htm

[technical details]

After applying MS03-048 patch, no javascript-protocol URL won't be stored in URL history list any more, which means classical "javascript-protocol URL in history" attack doesn't work any more.

(Liu Die Yu's http://www.safecenter.net/UMBRELLAWEBV4/BackMyParent2/index.html)

However, if an attacker do the following things:

Navigate a sub-frame in victim document to a javascript-protocol URL,

(first, navigate sub-frame to attacker's page, and then navigate the sub-frame a javascript-protocol URL)

and then navigate the top window away,

At last,navigate back("history.back()").

the javascript-protocol URL will be loaded by the top window(victim document) and script in the javascript-protocol URL will be executed in the security zone of victim document - a.k.a cross-site/zone/domain scripting

[Workaround]

Disable Active Scripting in INTERNET zone.

[Greetings]

greetings to:

Drew Copley, dror, guninski and mkill.

-----

all mentioned resources can always be found at UMBRELLA.MX.TC

[people]

LiuDieyuinchina [N0-@-Sp2m] yahoo.com.cn

UMBRELLA.MX.TC ==> How to contact "Liu Die Yu"

[message]

A wise man learns from other's mistakes; a fool learns from his own.

[Employment]

I would like to work professionally as a security researcher/bug finder.

See my resume at my site. I am very eager to work, flexible, and

extremely productive. I have a top notch resume, with credentials

from leading bug finders. I am willing to work per contract, relocate,

or telecommute.

[Give a Hand]

I haven't got a job as a security researcher yet and my family don't support my security work - so, I don't have a computer of my own. Please consider about donating at:

http://clik.to/donatepc

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus