6 ms·
At least on OSX 10.11 (not sure about others), you can't sniff loopback as a normal user. So, if you could sniff this, you'd have elevated privs anyway, which
by s800 11y ago
At least on OSX 10.11 (not sure about others), you can't sniff loopback as a normal user.
So, if you could sniff this, you'd have elevated privs anyway, which means you could read the keyboard device, memory, etc.
Not ideal, but not sure it's a glaring hole. IMHO. I'd love to hear other thoughts on how to exploit this / how I'm underestimating this hole.
- tptacek 11y agoThere is no modern OS on which you can sniff loopback without privileges.
- cortesoft 11y agoRight, but it looks like the process listening on the port is running as the user.... what is to stop another process running as the same user from killing that process and then binding to the same port?
- tptacek 11y agoNothing, but if you own the user's account, you also have their /Library directory to play with.
- richard_todd 11y agoRight, if you can watch loopback as a normal user, then the biggest problem is with machine configuration. After that, assuming the transmission has to happen, it's just a matter of how difficult you want to make it for root to see the passwords. Since you have to arrive at plaintext in the browser itself, everything a determined root needs to decrypt the transmission will be present on the machine anyway. Still, even a simple ROT-13 to keep an honest root from accidentally seeing the password would be welcome.
- tonywebster 11y agoThe author used `tcpdump -i lo0 -s 65535 -w info.pcap` which, as a non-root user without sudo, successfully captures loopback traffic in OS X 10.11.3. I just tried it, and with Chrome and 1Password, I was able to see my auto-filled bank password in the pcap. So, I presume any process on my system, without root privileges, would be able to sniff loopback. I don't see why 1Password wouldn't use TLS here. This is not good.
- tptacek 11y agoYour system is misconfigured. > $ tcpdump -i lo0 -s 65535 -w info.pcap tcpdump: lo0: You don't have permission to capture on that device ((cannot open BPF device) /dev/bpf0: Permission denied)
- tonywebster 11y agoThis is a fresh OS X install on a test machine :/
- tptacek 11y agoI don't know what to tell you. Normal users can't tcpdump loopback on OSX, or anywhere else. > $ ls -l /dev/bpf* crw------- 1 root wheel 23, 0 Feb 29 07:59 /dev/bpf0 crw------- 1 root wheel 23, 1 Feb 29 07:59 /dev/bpf1 crw------- 1 root wheel 23, 2 Mar 2 11:11 /dev/bpf2 crw------- 1 root wheel 23, 3 Mar 2 10:07 /dev/bpf3 crw------- 1 root wheel 23, 4 Feb 29 08:11 /dev/bpf4
- tshtf 11y agoWorks for me too on OS X. sudo is not needed to run tcpdump for any interfaces. $ ls -l /dev/bpf* crw-rw---- 1 root access_bpf 23, 0 Mar 1 09:18 /dev/bpf0 Edit: Wireshark is installed
- tptacek 11y agoDid you install Wireshark? Did you let it reconfigure your system? Is your current user in the "access_bpf" group? Later Yes. Your system is misconfigured. Don't let Wireshark do that.
- pvg 11y agoIt looks like Wireshark will happily keep your system permanently misconfigured. To fix it, disable /Library/LaunchDaemons/org.wireshark.ChmodBPF.plist This actually seems like a much crummier thing than the 1Password non-thing.