25 ms·
> The Signal devs thought $.html() does some kind of escaping: https://github.com/signalapp/Signal-Desktop/commit/9d41b8616.. https://github.com/signalapp/Signa
by grrowl 8y ago
> The Signal devs thought $.html() does some kind of escaping: https://github.com/signalapp/Signal-Desktop/commit/9d41b8616.. https://github.com/signalapp/Signal-Desktop/commit/9d41b8616.... (this commit made something that was easy to exploit into something that was even easier to exploit).
This is an absolutely egregious rookie error. I wouldn't touch the Signal desktop app with a 10 foot pole after seeing that commit.
- cyphar 8y agoWhat's incredible is that the author actually had to modify an XSS test so that it read: > const expected: string = "Hello<br><script>alert('evil');</script>World!"; (Meaning they actually changed a line that had "<script>alert('evil')</script>" and didn't notice.) I have seen this before though, with some folks removing path sanitisation code I added several years prior to fix a CVE. So it's not uncommon (it also got merged, so when I found out and fixed it I added a very large and scary comment to stop people from doing it again).
- mercer 8y agoWhy is this a 404 now?
- Stephen304 8y agoLooks like grrowl copied and repasted the truncated display text of the link. The full link is 2 comments up: https://github.com/signalapp/Signal-Desktop/commit/9d41b8616296f1b328aa864e0114b99d7f11ca06 https://github.com/signalapp/Signal-Desktop/commit/9d41b8616...