3 ms·
Your example makes it look like this is doable to any site that allows JSONP responses that contain sensitive data. Is this RoR specific because RoR will alway
by KayEss 13y ago
Your example makes it look like this is doable to any site that allows JSONP responses that contain sensitive data.
Is this RoR specific because RoR will always allow JSON responses to be turned into JSONP, or is there something else at work?
I'm suddenly pleased I've been holding off on doing JSONP as part of Django Slumber.
- KayEss 13y agoI just managed to confirm that a similar attack is possible against sites using DjangoRestFramework. I won't publish it as the site I used to test against is currently working on patching the vulnerability out.
- tomchristie 13y agoIf you believe you've found a security issue in Django REST framework I suggest raising emailing the security contact as listed here: http://django-rest-framework.org/#security http://django-rest-framework.org/#security Having said that, it's worth pointing out that Django REST framework does not return JSONP by default, and although it does for historical reasons include a JSONP renderer, the documentation recommends the use of CORS instead.
- KayEss 13y agoI did email it pretty much straight away, but I guess it didn't get through.
- homakov 13y ago>Is this RoR specific because RoR will always allow JSON responses to be turned into JSONP, or is there something else at work? you can't turn any JSON into JSONP. No, JSONP here is result of using RJS templates. It has nothing to do with original JSONP
- KayEss 13y agoExcept inasmuch as you're using a framework that allows any JSON data to also be requested as JSONP. The very first site I checked on this (which uses DjangoRestFramework) I was able to access email addresses from an attack page. This is purely due to DRF handling the JSONP for you without the devs really being aware of what was going on.
- homakov 13y agothis is slightly different vulnerability (JSON->JSONP upgrade) but it's really severe. Good find!