Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kdarutkin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
Open source website bundle analyzer that shows vulnerable NPM packages
(gradejs.com)
7 points
by
kdarutkin
4y ago
|
1 comments
2.
▲
by
kdarutkin
4y ago
I’d like to share an open source project I’ve been working on during the last year. It analyzes production JavaScript code and detects bundled NPM package versions. A vulnerability is shown when a specific detected version contains known vu
3.
▲
by
kdarutkin
5y ago
It is possible on Tor Browser. Chrome and Firefox show a confirmation popup in the main frame.
4.
▲
by
kdarutkin
5y ago
Wow, that's weird. The internet connection may be the issue here, or the custom configuration on Safari.
5.
▲
by
kdarutkin
5y ago
Thanks for the feedback. The accuracy is the main issue on Chrome. See also https://news.ycombinator.com/item?id=27147876
6.
▲
by
kdarutkin
5y ago
We haven't tested Vivaldi so far and the demo is not designed for it. However that doesn't mean Vivaldi is secure against this attack.
7.
▲
by
kdarutkin
5y ago
This is possible in theory. For example, Safari opens the Apple Music without any user prompt. The app itself is designed to handle deep links (such as opening an album or starting the song). That means you can perform a deep link forgery,
8.
▲
by
kdarutkin
5y ago
We will make a detailed report with some statistics, after the vulnerability is fixed
9.
▲
by
kdarutkin
5y ago
Mostly because it took hours to make an exploit on Safari compared to days on Firefox, however the final approach ended up the same. Only Chromium has a built-in scheme anti-flooding protection.
10.
▲
by
kdarutkin
5y ago
Edge 90 is also affected. We tested it on Windows 10.
11.
▲
by
kdarutkin
5y ago
Thanks. Linux is tricky. Mostly because Chrome opens applications through `xdg-open`. Custom configuration on Firefox may also affect the result.
12.
▲
by
kdarutkin
5y ago
I also made a special branch for Chromium (Chrome, Brave, Edge, etc.) that works much slower, but should be more accurate. It still may not work for your browser with a custom configuration. Also, it is better not to make any gestures durin
13.
▲
by
kdarutkin
5y ago
I’m the author. The accuracy can be low because of: - Custom browser settings or flags - The demo was designed for the default setup, but that doesn’t mean your custom setup is not vulnerable. - Poorly performant hardware (including virtual
14.
▲
by
kdarutkin
5y ago
Hi, agilob. I've updated the demo for Chromium and made it work slower, in order to increase accuracy. See also https://news.ycombinator.com/item?id=27147325
15.
▲
by
kdarutkin
5y ago
Chromium results may be flaky on slow internet or because of less performant hardware (such as Virtual Machines). I've updated the demo for Chromium and made it work slower, in order to increase accuracy.
16.
▲
by
kdarutkin
5y ago
The exploit was tested in Safari 14.0.3 and 14.1 on MacBook M1 and MacBook Pro. What version do you have?
17.
▲
by
kdarutkin
5y ago
Any custom settings may affect the result. However default settings will work for the Firefox 88.0.1. Was tested on Windows, Safari and Linux. Chrome does not work on Ubuntu, since it opens everything with xdg-open and creates confirmation
18.
▲
by
kdarutkin
5y ago
Hi, nimbius. I’m the article author, can you please clarify your question? The demo will not work without a popup window in Chrome, Firefox and Safari. The “Get My Identifier” button is needed in order to have a single user gesture to open