9 ms·
Protecting sites from Cryptojacking with CSP and SRI
- lerie82 9y agoOnce upon a time I was a little ol' kiddie "compromising" websites. One day I thought to myself, what am I doing? Why don't I just replace their ads with mine and reap the benefits. So I did. I had hundreds of dollars overnight from online advertising that I had stolen. Google sent me a nice email saying they had known what I did and should pay the money back. If I did it again or my account was caught in any kind of fraud it would be banned. Cryptojacking is no different, it isn't some new hacking technique, it's not a new method or exploit, vulnerability or whatever you want to call it. Giving it a name like this gives it power and recognition and will let other "script kiddies" start using this when they infect the server with their gibberish. Basically it's an rfi/lfi, but with their js miner instead of a "shell". I hope more researchers and enthusiests don't feed this, but they will, and it will be nothing but negative and draw a younger crowd into hacking (which could be good, since that seems to be how the industry draws in new 'good' researchers).
- walterbell 9y agoWhat percentage of mainstream sites use the "integrity" hash validation attribute when loading 3rd-party script for a known-good library version? Would be a useful data point for a "tech stack" web crawler to monitor.
- deleted 9y ago[deleted]
- greglindahl 9y agoUse of integrity hash validation is pretty limited -- I see 90k sites in the top 10 million. It's a shame this isn't more popular, I'd love to build a browser add-on that uses the integrity hash as the name of the script, and load them from ipfs or something. Top sites: gov.uk, nhm.ac.uk, change.org, blogs.worldbank.org, handbrake.fr, army.mil, genome.gov, ...
- K0nserv 9y agoSRI[0] is still a fairly new technology with lacking browser support. I expect its usage to grow, but it's worth keeping in mind that the use of SRI does not matter at all if the client doesn't support SRI. 0: SRI - Subresource Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- greglindahl 9y agoAs a guy who crawls, indexes, and archives websites, subresource integrity matters to me whether or not the client supports it. You probably had end-users in mind.
- K0nserv 9y agoYeah exactly I was thinking of end users. Since the support in end user's client dictate what websites will implement I think we'll see use of SRI increase over the coming years
- greglindahl 9y agoI would be amazed if anyone disagreed with you about that. Status of client support: https://caniuse.com/#search=integrity https://caniuse.com/#search=integrity
- raesene9 9y agothat info. on the level of support is v. interesting, is there any published data on it that could be linked to (blog posts, web site etc)?
- greglindahl 9y agoThere are a bunch of crawlers that aggregate that kind of info -- I'm building a new search engine, and I'm not in the business of publishing stuff that would encourage anyone to block my crawler. builtwith.com is an example, but they're being pretty strict with what you can see for free these days. And hey, they only know about 2k sites using script integrity, so maybe I've got a bigger crawl than they do! :-)
- neals 9y agoThis makes me wonder what happens when a popular nodejs library get used in this way. What could hackers do with thousands of compromised nodejs servers?
- gboudrias 9y agoNowadays it's just about getting as many miners as possible. No big mystery.
- quickthrower2 9y agoWell they might do other things in to your house, now they have the keys.
- raesene9 9y agoyeah the complete lack of signing on npm libs + the large dependency trees that can trip you up (e.g. the leftpad problem) are only going to cause more issues as attackers move on to that as a vector.
- stri8ed 9y agoProof of stake will solve this.
- IncRnd 9y ago> Proof of stake will solve this. No. It. Won't. The issue isn't PoW/PoS but the loading of infected code into browsers. PoS may stop the need for this particular JS code to get inserted. However, PoS will hinder no other JS from being inserted.
- JoachimSchipper 9y agoIn principle, sites should be secure. In practice, putting an implicit bug bounty on every widely-used Javascript library does produce more exploitation. I think you missed an opportunity to engage your parent comment more productively.
- IncRnd 9y agoWhat principle states sites should be secure? There is hardly even a nod to security, no defense in depth, and no cryptographic protections. There is widespread loading of untrusted unvetted code. The operating principle of the web seems to be, "it's okay to do this, everyone else is."
- deanclatworthy 9y agoThere’s still large numbers of people on older browsers that don’t support the integrity attribute. It’s not foolproof but it’s one of those things you can do to improve the experience and security with no side effects to older browsers and benefits to new(er) ones.
- userbinator 9y agoPresumably, the "[Warning] Do not copy or self host this file, you will not be supported" is because they change the script reasonably often, meaning that using SRI will require them to change their hashes on every linked page every time the script changes or it will stop working --- probably not what they want. when visiting the ICO website That is... amusingly ironic.
- deleted 9y ago[deleted]
- Scott_Helme_ 9y agoYeah, the best way to handle this is with a version in the path and then the host can knowingly/willingly upgrade the library version and SRI hash at the same time.
- cbr 9y agoThat doesn't really solve this problem, it just slows down both the rollout of the subverted version and the rollout of the fix. People aren't auditing the (minified) javascript they put onto their sites. SRI is good for use with a CDN, where the same entity controls both the HTML that references the JS and the JS being referenced. In that case it keeps someone who subverts the CDN from being able to XSS the site.
- greglindahl 9y agoThat depends on what "this problem" is -- lots of people here would say that the problem is websites that depend on unaudited, untested 3rd party resources. I can tell from your other comments that you think it's safe to trust 3rd party resources from places like Google. So there's a disagreement that is worth talking about explicitly.
- cbr 9y agoMost sites are built on lots of unaudited untested (by them) third party code sever side. Adding some client side isn't great, but also isn't a fundamental change to the dynamic. (I used to make web server software)
- rexbee 9y agoHere's a list of hundreds of sites using that JS library https://nerdydata.com/search?query=www.browsealoud.com%2Fplus%2Fscripts%2Fba.js https://nerdydata.com/search?query=www.browsealoud.com%2Fplu...
- jnordwick 9y agoWhen will the JavaScript community learn to stop trusting 3rd party code downloaded over the internet? In the previous event the code disappeared. This time it isn't what you wanted.
- userbinator 9y agoWhen will the JavaScript community learn to stop trusting 3rd party code downloaded over the internet? Given that the majority in the JS community probably have it enabled by default in their browsers, probably never...
- floatboth 9y agoNot 3rd party in relation to the user's machine. 3rd party in relation to the site. As in <script src="https://someone.elses.domain/something.js"> https://someone.elses.domain/something.js">
- badwebsite 9y agoThose are the same thing
- petagonoral 9y ago> What I've done here is add the SRI Integrity Attribute and that allows the browser to determine if the file has been modified, which allows it to reject the file Wouldn't this negate one of the benefits of a 3rd party hosted SaaS? Otherwise, you have to redeploy everytime your provider updates their lib?
- teej 9y agoIt’s not uncommon to freeze 3rd party libs. Do you want a 3rd party provider to have access to hot deploy to your website?
- gokhan 9y agoPossible if the 3rd party script is versioned.
- stordoff 9y agoIsn't that the same as freezing the script (except still loading from a remote and using SRI to enforce that it wasn't changing)?
- petagonoral 9y ago> It’s not uncommon to freeze 3rd party libs Sure. 3rd party libs your code uses directly. Haven't seen it too much with 3rd party service providers code that are somewhat outside your code boundaries. Taking 2 different popular 3rd party SaaS that are included as JS in sites as an example. Google Analytics uses url of https://www.google-analytics.com/analytics.js https://www.google-analytics.com/analytics.js [1] Stripe uses url of https://js.stripe.com/v3/ https://js.stripe.com/v3/ [2] < Do you want a 3rd party provider to have access to hot deploy to your website? Clearly not. Nor was this inferred. [1] https://developers.google.com/analytics/devguides/collection/analyticsjs/ https://developers.google.com/analytics/devguides/collection... [2] https://stripe.com/docs/stripe-js/reference https://stripe.com/docs/stripe-js/reference
- mholt 9y agoEven when using integrity checksums, you have to be careful not to update them to match the malware, like brew did with Handbrake a while ago: https://github.com/caskroom/homebrew-cask/pull/33354 https://github.com/caskroom/homebrew-cask/pull/33354
- sitkack 9y agoIsn't this literally out of 'How I Steal Your Credit Card Number' playbook?
- bluejekyll 9y agoIt’s similar. If I remember the CCN playbook correctly, it was about taking over one of your JS dependencies via npm. This is about cross hosted JS, loading remote code.
- Scott_Helme_ 9y agoMore or less, yeah..
- deleted 9y ago[deleted]
- Mister_Snuggles 9y agoI use uMatirx and it’s given me a pretty good lesson on how much stuff sites load from 3rd-parties. Many sites need me to play whack-a-mole to get them to display - which 3rd party sites do I need to allow to get the content to show up. I’m really torn by this sort of thing. On one hand, when many sites use jQuery (for example), there’s huge benefits (bandwidth, speed, etc) in having it loaded from one location relatively infrequently and cached for many pages. This is exactly the promise of shared libraries, just on a much wider scale. On the other hand, why aren’t web site operators delivering all of the code that is needed for the site to function? If they want all their users to execute that code, why aren’t they willing to serve it themselves? I’m not sure what the right answer is, but this incident is a pro for pulling in all of your dependencies. The limited data plans that a lot of people have are a big pro for hosting libraries centrally.
- amenghra 9y agoThe right answer is to specify a HMAC when serving js from third parties. CSP/SRI already enables this. Ideally you should be able to serve content from your own domain + specify the hash, and let browsers optimize things by re-using cached content from another domain. There’s no easy/standardized way of doing that today.
- greglindahl 9y agoI think you can already do a browser extension that intercepts loads and gets things with script integrity from a cache, another domain, ipfs, whatever. Decentraleyes is an example of an existing codebase you could use: https://github.com/Synzvato/decentraleyes https://github.com/Synzvato/decentraleyes
- Scott_Helme_ 9y agoThere is/was discussion in the standards body of using the SRI hash for exactly this purpose. It sounds really promising but iirc there was a privacy kink to work out.
- sago 9y ago
- Feniks 9y ago"On top of all of that, you could be alerted to events like this happening on your site via CSP Reporting" Too bad this can be abused by marketing parasites.
- orf 9y agoHow?
- dullgiulio 9y agoCSP reporting is an unprotected form, in itself a vulnerability. The author of the article is biased as he made a SaaS product for CSP reporting. CSP reporting should be for local debugging only.
- orf 9y agoI'm sorry, I'm still not following. How can CSP reporting be used by marketers? It requires a header sent from the server, so it's not like a tracking pixel that can be added by a third party. And I'm not sure about local debugging only, locally it offers no benefits over just viewing the devtools console, whereas it offers a lot of benefits when enabled on users of your sites.
- cbr 9y agoWant to know how you can easily stop this attack? What I've done here is add the SRI Integrity Attribute and that allows the browser to determine if the file has been modified, which allows it to reject the file. SRI does not fix this problem. If you put an integrity attribute on the script, then the next time BrowseAloud releases to prod their script will stop working on your site. This is a product that works by running a script on your page to make changes. There's no option for defense in depth here: either you trust that their processes are secure enough that they're not going to XSS you, or you shouldn't run their code on your site at all. The bar for including javascript from other sites should be a high one, but there are times when the tradeoff is reasonable. For example, I have Google Analytics [1] on my site, and I trust them to handle this responsibly. [1] Disclosure: I now work for Google
- Kenji 9y agoI really see no reason why anyone would include JS files from other sites. I regularly see people including jquery from google or other sources. Why the hell? You can't host a little JavaScript file yourself? What's wrong with web devs these days??
- gambler 9y ago>The bar for including javascript from other sites should be a high one Yes, but that's not how most developers think these days. Try browsing the Web with NoScript and you will routinely witness dozens of domains in the block list.
- throwawaypanda 9y ago>The bar for including javascript from other sites should be a high one >but that's not how most developers think these days. The decision to include third party javascript is sometimes not even up to developers these days. "A deal has been signed with company X, put their widget on the site" is something I've now heard a few times. Arguments about the third party code greatly increasing page load time, page size, introducing security vulnerabilities etc then fall on deaf ears. High developer turnover seems to co-occur in these environments.
- gambler 9y agoContent-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-XSS-Protection, X-Content-Type-Options, Access-Control-Allow-Origin... How many hacks like these will we need before people stop to rethink the fundamental security model underpinning the Web? It's clearly crumbling.
- JetSpiegel 9y agoWe are clearly in the Antivirus level of protection (blacklists) to maintain backwards compatibility, instead of a whitelist of allowed domains or features to use.
- ubernostrum 9y agoCSP is a whitelist-based approach; CSS/JS/etc. will only be permitted from the sources listed in the CSP header.
- baybal2 9y agoA useful tech it is. The problem is 3rd party code from adnets is changing all the time, and they will never tell you about that because they hide all kind of anti-clickfraud trick there. From intentionally broken JS syntax, to intentionally broken Unicode, to actual 0day exploits.
- rspeer 9y agoWhen I first read this discussion, I just assumed that BrowseAloud was some sort of ad-tech or analytics code. But it's assistive technology for screen readers. The list of web sites that were compromised were web sites that were trying to do the right thing to help disabled users. Ad-tech is a giant security hole that can't be fixed without burning it all down, but BrowseAloud could be fixed.
- kevin_b_er 9y agoI consider ad-tech to be fundamentally malicious and block it. It is only reasonable course of action.
- baybal2 9y agowe used to do an ajax load of a resource and doing simply hash of it "by hand," sending "alarm, lib A has suddenly changed" by ajax to HQ
- deleted 9y ago[deleted]
- jschwartzi 9y agoHow would I get Mozilla to warn me when a script is loaded without Subresource Integrity? I'd like to avoid being caught unawares by this type of security hole, especially if it lets third parties execute code in my browser without any controls.
- hyperpape 9y agoI think adoption is limited enough that you just need to run NoScript, uBlock or something and whitelist JS.
- quickthrower2 9y agoSomething like JS 'permissions' could help here. I.e. load a script but limit how much CPU/GPU access it has plus determining if it has DOM access, XHR access, etc. So you load the script and tell it what it can do. Also developers taking security more seriously. But it is rarely a priority, since risk reduction is not paid for today.
- shrumm 9y agoI like this option, similar to how apps request permissions on a mobile OS. There could be a default list of modifications an external javascript script can run, any further access must be explicitly white listed by the developer. Then even if the script was malicious, at least the impact is controlled. for instance, maybe the default is that an external script can read the DOM but needs extra permissions to write/modify it?
- Quarrelsome 9y agoam I weird in that I'd prefer to host a known version of a dependency than effectively hot-link like this? Avoiding this sort of attack is a just a side-benefit to the main premise of knowing that its always going to work consistently.
- skinpop 9y agomaybe we should throw out ads and instead let creators borrow our computers to mine for a few minutes while we interact with their content.
- stordoff 9y agoI suspect what we'd actually end up with is miners PLUS ads. There's little incentive to not use both forms of monetisation, as neither prevents the other from being used. I also don't think it's a great trade-off for a variety of reasons (environment impact, possible wear and tear on user's machines, battery life on mobile devices etc.).
- nodesocket 9y agoIf you use 3rd parties such as analytics and chat scripts you don't have control if they legitimaty change the response. I get it, they are supposed to use versioning and bump, but you'd be surprised. All your hard coded hashes fail and your 3rd party analytics, chat, etc all stop working. Is there a solution to that?