4 ms·
Won't solve the problem completely, but what about removing eval from the spec? Or making us obfuscation more difficult?
by dpweb 10y ago
Won't solve the problem completely, but what about removing eval from the spec? Or making us obfuscation more difficult?
- jerf 10y agoI'm not sure what eval has to do with the specific problem, but you actually can nuke eval from your website in most browsers now with a header: https://en.wikipedia.org/wiki/Content_Security_Policy https://en.wikipedia.org/wiki/Content_Security_Policy You could also prevent this problem in general with Content Security Policy, by whitelisting only the domains you know JS should come from. Then, even if they do in fact get a script tag on to your page pointing at a hostile domain, it won't execute unless they also nuke your CSP headers. You can even set up your CSP such that it notifies you upon violations. In theory a hacker could still penetrate all that in one shot by disabling your CSP and then adding their script, but it means if they miss the CSP even briefly that you have at least a chance to be notified before they square it away. It at least raises the bar. But the real problem here is that we're not generally talking about people who know about CSP, nor is it generally reasonable to expect they would or could, at least right now. It's pretty niche stuff in general. I'm sure if I gave a quiz on CSP here, a ton of people could reply with the correct answers, some of them even without Googling, but in general if I talk to my coworkers about that I'm doing well to get a vague "Yeah, I've heard of that I think..."
- nateberkopec 10y agoIn this case, since the attacker has access to the source code, they could easily disable a site's Content Security Policy.
- jerf 10y ago"Raises the bar", I did say. They have access but if they're only accessing it through an automated system they may miss it. Plus, I should have pointed out that CSP can be applied at higher layers, including nginx itself or a WAF, that the attacker may not be able to access or modify. I didn't think of it at the time.
- nateberkopec 10y agoGreat point, I didn't think of that either.