5 ms·
Just one additional note that might not be immediately clear from the advisory: Exploiting this requires the attacker to first manually place malware (a malicio
by jlund 8y ago
Just one additional note that might not be immediately clear from the advisory: Exploiting this requires the attacker to first manually place malware (a malicious JavaScript file) on your computer or on a Samba network share that your computer is already connected to.
- bjoli 8y agoYeah. That fact seems pretty hidden in the reports. Due to proper CSP only local files will be executed. If you are who I think you are, maybe you could speculate if there is actually any use for this other than loading local files (local file execution) and crashing signal?
- nitrogen 8y agoIf a .js file is redirected to from a web page, with a Content-Disposition header marking it as a download, and (as is common) the browser downloads automatically to ~/Downloads, doesn't that leave the .js file in a predictable place that can then be used by an attack on Electron?
- bjoli 8y agothat could probably.be answered by jlund. Electron downloading things by default seems like a pretty bad thing to do.
- jlgaddis 8y ago> ... or on a Samba network share that your computer is already connected to. Does CSP prevent this working with, for example, a malicious.js file on a remote, attacker-controlled Samba server (configured to allow "anonymous" connections)?
- aegarbutt 8y agoThe CSP policy was 'self'. The problem is that all file:// URIs share an origin in Electron. So, 'self' is ALL file:// URIs.
- aegarbutt 8y agoOr I just expose my malicious share to the Internet. No mounting step necessary. file://<Evil-IP>/evil.js
- aortega 8y ago> Exploiting this requires the attacker to first manually place malware (a malicious JavaScript file) on your computer or on a Samba network share that your computer is already connected to. I'm Alfredo Ortega, part of the team that wrote the original exploit. This is (unfortunately) not true. The exploit on the video was loaded from a Windows share that the victim's computer was not already connected. This is possible using "Anonymous shares" in Windows 10, and older windows versions. To be clear, you need absolutely no additional software on the victims computers, besides having a vulnerable signal-desktop and be running on windows.
- jlund 8y agoI was incorrect about this, and I apologize.