9 ms·
I'm Joining Report URI
- fredley 9y ago> ...embeds an XSS attack in the TXT record of a DNS entry which then renders into the output of a WHOIS service I'm not even mad, that's amazing.
- vim_wannabe 9y agoRemember kids: raw input, escape output.
- technion 9y agoThere was a particular domain that, when queried at most whois services, would play the harlem shake in your browser. It worked nearly everywhere that did such lookups.
- astura 9y agoIt was linked in the next sentence of TFA: https://www.youtube.com/watch?v=1anIUDvdCjY https://www.youtube.com/watch?v=1anIUDvdCjY The domain was forfun.net
- helb 9y agoThere's even a tool for it: https://wiki.skullsecurity.org/index.php?title=Dnsxss https://wiki.skullsecurity.org/index.php?title=Dnsxss
- guessmyname 9y agoI used to do this with because I found that some web performance scanners would usually forget to escape the content of the HTTP headers. After sending this domain [1] some of them would immediately execute the script. Feel free to send a HEAD request to this website so you can understand better, it's basically the same thing as with the TXT DNS records. [1] https://cixtor.com/ https://cixtor.com/
- onli 9y agoIs the HPKP he mentions as a security measure the same public key pinning chrome did just announce the deprecation date, because it is too risky to do; or are these different concepts?
- lmm 9y agoIt's the same thing. There are some differences of opinion on the matter.
- hdhzy 9y agoActually Scott Helme (mentioned in the article) also came to the conclusion that HPKP does more harm than good: https://scotthelme.co.uk/the-death-knell-for-hpkp/ https://scotthelme.co.uk/the-death-knell-for-hpkp/
- _pdp_ 9y agoIs it really a failure if X-Frame-Options header is missing on a blog? If it is a failure then why not just make it not possible to use iframes at the browser level. Without context, this service misrepresents the real security of any given site.
- billyhoffman 9y agoTo be fair, the challenge of nearly all security assessment tools, including Security Headers, is they don't understand the context of what they are assessing. X-Frame-Options on a blog isn't a big deal. X-Frame-Options on a SaaS app can be. That's why blindly scanning something and then saying "look at all these vulnerabilities" is a pretty poor way to assess the security of a service.
- runesoerensen 9y agoWhat a great "I'm joining" post! Congrats Troy and Report URI
- ing33k 9y agoI really hope that this somehow will improve the adoption of CSP. Getting CSP right is quite hard and I have seen many big sites just using it in report only mode ( forever).
- kogepathic 9y agoReport URI appears to depend on CSPs being submitted. There was recently a discussion about uBlock Origin blocking CSPs on privacy grounds. [0] So this will only work for sites that use CSP and users who don't have uBlock Origin installed, unless uBlock Origin changes their default policy on CSPs. ninja edit: I see uBlock Origin has changed their defaults to permit CSP submission [1] [0] https://www.theregister.co.uk/2017/10/17/ublock_origin_csp_reports/ https://www.theregister.co.uk/2017/10/17/ublock_origin_csp_r... [1] https://github.com/gorhill/uBlock/issues/3140 https://github.com/gorhill/uBlock/issues/3140
- j_s 9y agoTroy very publicly carrying water for Scott Helme/Report URI looks quite a bit different in hindsight, as the number of Report URI marketers doubles to 2. · https://twitter.com/troyhunt/status/920590590223331329 https://twitter.com/troyhunt/status/920590590223331329 · https://twitter.com/troyhunt/status/920222303849390081 https://twitter.com/troyhunt/status/920222303849390081 · https://twitter.com/troyhunt/status/920173854835720193 https://twitter.com/troyhunt/status/920173854835720193 The uBlock Origin dev compromised with an opt-out for CSP reports, even though they can be used for things like IP address leaks to 3rd party servers (similar to the as-seen-in-court Tor-busting captcha mess). Personally I would prefer only same-origin reports. -- My biggest problem in all of this is that Scott was not careful to always document his not-quite-obvious conflict of interest, and even worse: Troy's association is only now being revealed weeks later. I do appreciate the work being done to improve the effectiveness of CSP reports in default configurations of open source tools, but can't help wondering about the motivation. Disclaimers go a long way toward keeping unsuspecting maintainers informed of both sides of an issue. · https://github.com/issues?utf8=%E2%9C%93&q=is%3Aissue+author%3Ascotthelme+CSP https://github.com/issues?utf8=%E2%9C%93&q=is%3Aissue+author... · https://twitter.com/Danbo/status/920325189954654208 https://twitter.com/Danbo/status/920325189954654208 Scott was also blamed here on HN last week for his part in promoting the death of HKHP (public key pinning) apparently due to ease of misconfiguration. · https://news.ycombinator.com/item?id=15573076 https://news.ycombinator.com/item?id=15573076 Looking back now I'm left wondering how HKHP affected Report URI and Scott's other project, Security Headers. I will disclose my bias as I watch highly effective marketing of convenience (top of HN!) triumph over my personal flavor of slightly paranoid privacy yet again.
- rdslw 9y agoIf you don't know who is Troy Hunt, then one thing to do right now is to signup for his great service: https://haveibeenpwned.com/ https://haveibeenpwned.com/ in essence, everytime(+) some massive break occurs, and your e-mail (and probably password) is among them after reaching "darknet" (meaning black market), you will get from haveibeenpwned an e-mail, urging you to some action (password change, account closure/change etc). (+) Troy amassed over the years huge db of past breakins (so you can check your email presence also in past events) and with current respect/reputation he gots access to new ones pretty fast, informing you instantly in most cases. Highly recommended.
- throwaway613834 9y ago> after reaching "darknet" (meaning black market) > with current respect/reputation he gets access to new ones pretty fast, informing you instantly in most cases So he has the respect of (street cred with?) the dark net/black market folks and that's how he gets them instantly? Or I suspect you meant to say something slightly different?
- NKCSS 9y agoThese lists get 'traded' amongst security professionals a lot. Quite a few of them will send Troy a copy to load in to HIBP.
- weinzierl 9y agoI don't know how he obtains the data, but in [1] he makes a point of never having paid for it. > I've also never paid for data nor traded any of the breaches I've obtained. [1] https://www.troyhunt.com/thoughts-on-the-leakedsource-take-down/ https://www.troyhunt.com/thoughts-on-the-leakedsource-take-d...
- blfr 9y agoYou can sign up your entire domain if you control the postmaster@ address.
- buro9 9y ago
- ishitatsuyuki 9y agoSentry can also handle CSP reports effortlessly, and it's all open source. I had a quite good experience with their ease to use UI.
- skrebbel 9y agoI don't get it. What does Report URI do? Their landing page doesn't say. And Troy Hunt's blog post tells me this: * Set up CSP headers * Somehow, magically, Report URI will tell you things Wait what? How does that work? I feel like I'm missing a step. Unfortunately https://report-uri.com/ https://report-uri.com/ doesn't really explain either, or have integration docs of any kind. I'm not trying to be snarky, I'm considering to become a customer.
- lstamour 9y agoYou can set CSP headers that browsers will read for content security policy (to prevent or notice unusual content includes or sources). There can be two consequences: violations can be blocked, or they can load but get reported in console. If a URL is set in the CSP header, the browser can report the violations to another URL for inspection and tracking. For the details, see https://www.w3.org/TR/CSP3/#report-violation https://www.w3.org/TR/CSP3/#report-violation Like error tracking, the tricky bit isn’t always the reporting, it can also be learning to ignore errors caused by extensions, or grouping and alerting on issues in report-only mode such that they can be fixed in a timely fashion. That said, even knowing what to use as a CSP header can be daunting, so there’s plenty of room to make this powerful security feature easier to use.
- johnlbevan2 9y agoTo get this reporting to work, you need an HTTP header in place. Historically (fairly short term history) this was "report-uri"; hence the name of their product... however this has since been replaced by "report-to". More information on these headers can be found here: https://developer.mozilla.org/en-US/docs/Glossary/Reporting_directive https://developer.mozilla.org/en-US/docs/Glossary/Reporting_... (at time of writing the `report-to` documentation is pending)... Steps: - User's browser loads your page - User's browser detects something which would be a violation of your CSP policies - User's browser blocks that content... - ...and also checks for a Report-To, Report-URI, or CSP-Report header in the HTTP Headers. - If any of those headers exist, the user's browser makes an http post to the stated URL, passing information about the problem. - If the URL stated in those headers was the Report-URI.com service's URL (i.e. the service which Troy Hunt's writing about) then their company receives this data, and can use the information in that to determine that this report relates to your website (i.e. from the info in the `document-uri` field), and store this information in the metrics they provide for your site.
- mkagenius 9y agoIsn't it pretty easy to exhaust anyone's quota -- for the write key is visible in html source code? However it is not specific to this service but I have always wondered why this design(write key public and quota system) works, while it shouldn't.
- jakobegger 9y agoThere's nothing to gain from exhausting someone else's quota. People will go to great lengths to exploit anything for profit, but just messing with other people without anything to gain personally -- that's not a good motivation.
- Ajedi32 9y agoDDOS attacks are a well-known attack that falls under the same category. I wouldn't be so quick to dismiss this as a valid concern.
- j_s 9y agoI'm assuming this is the standard technique, like the Google Analytics tracking id.
- brunoqc 9y agoFor CSP also check this great Firefox add-on by Mozilla https://addons.mozilla.org/en-US/firefox/addon/laboratory-by-mozilla/ https://addons.mozilla.org/en-US/firefox/addon/laboratory-by... . It generates and allow you to test the CSP header.
- tiernano 9y agoOk... So... i just signed up, and it walked me though some steps. Verify Email: Done, Customize (change reporting URL): Done... Configure: (change some domain filters)... Done... 2FA: Done... but how do i actually set this up?! like, what do i need to put on my site to enable this?! WTF?! is this done at a page level? (HTML inserted into the page) is it at a server level (Nginx, Apache?) Or is it done somewhere else?! where do i set this up?! more digging required, but it would have been handy to have a guide for what i need to install...
- Ajedi32 9y agohttps://report-uri.com/account/setup/ https://report-uri.com/account/setup/ But yeah, it seems like they could really use some instructions on how to set this up for people unfamiliar with how the Web Reporting API works. The documentation you're looking for is here: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/report-uri https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...
- aspett 9y ago> Deprecated > This feature has been removed from the Web standards. Though some browsers may still support it, it is in the process of being dropped. Ok..
- Ajedi32 9y agoKeep reading: > Though the report-to directive is intended to replace the deprecated report-uri directive, report-to isn’t supported in most browsers yet. So it's deprecated, but until it's replaced by report-to (which works in a very similar way) report-uri is still the proper way to make this feature work. I would have linked to report-to instead, but MDN doesn't have good documentation on that yet.
- negativ0 9y agowhat about, who cares?
- sctb 9y agoCould you please stop commenting like this? https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- trumpownsyou420 9y agono one cares.
- delhiitem 9y agoI don't get what the product is about
- Jtgx 9y agoI found https://haveibeenpwned.eu https://haveibeenpwned.eu and https://haveibeenpwned.ninja https://haveibeenpwned.ninja don't use Report URI