Will NoScript stop recently discovered SVG Keylogger

General discussion about the NoScript extension for Firefox
Post Reply
mcgyver5
Posts: 2
Joined: Fri Jan 06, 2012 6:17 pm

Will NoScript stop recently discovered SVG Keylogger

Post by mcgyver5 »

A recent CNET article http://download.cnet.com/8301-2007_4-57 ... ?tag=mncol
about a Keylogger attack via a browser SVG flaw mentions NoScript but seems to indicate that NoScript would not stop this.

I have "Block every object coming from a site marked as untrusted" checked. Wouldn't this prevent SVG objects?
Last edited by mcgyver5 on Fri Jan 06, 2012 9:58 pm, edited 2 times in total.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Will NoScript stop recently discovered SVG Keylogger

Post by therube »

Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:11.0a2) Gecko/20120105 Firefox/11.0a2 SeaMonkey/2.8a2
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Will NoScript stop recently discovered SVG Keylogger

Post by therube »

Interesting.
"The basic premise of my research currently is scriptless attacks, meaning attack vectors working in a post-XSS world," Heiderich said in an e-mail. He defined a "post-XSS" world as one where the cross-site scripting attack had been more or less minimized by technologies like sandboxed iFrames, Mozilla's e-mail client Thunderbird and Firefox's Content Security Policy, the JavaScript blocking browser add-on NoScript, and Windows 8.
And if done, then it makes the web far more dangerous.
At present, you've got to think that for the average badguy, JavaScript is just too easy to go scriptless.
In any case, you know scriptless will come, just a matter of time & cost/benefit to the badguys.


If NoScript blocks SVG (don't know if it does?), if SVG is considered an Embedding, where Forbid other plugins would cover it, then you could be protected in that respect?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:11.0a2) Gecko/20120105 Firefox/11.0a2 SeaMonkey/2.8a2
mcgyver5
Posts: 2
Joined: Fri Jan 06, 2012 6:17 pm

Re: Will NoScript stop recently discovered SVG Keylogger

Post by mcgyver5 »

thanks, I fixed the link. When I check "Block Every object coming from a site marked as untrusted", all SVG elements on pages are blocked, as far as I can tell...
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Will NoScript stop recently discovered SVG Keylogger

Post by Giorgio Maone »

NoScript has been providing specific protection against this kind of attack since before it was revealed:

Code: Select all

v 2.2.2rc1
==========================================================================
+ [XSS] Explicit check for potentially dangerous SMIL elements (thanks
  .mario for suggestion)
+ Protection against scriptless keylogging (thanks .mario for reporting)
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3369
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: Will NoScript stop recently discovered SVG Keylogger

Post by GµårÐïåñ »

As Giorgio already pointed out, this is already moot and has been for a while. Unless a POC showing currently it can defeat NS, we are in the clear. Hence why people should beware on Chrome and such browsers WITHOUT NoScript.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows NT 6.1; rv:8.0) Gecko/20100101 Firefox/8.0
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Will NoScript stop recently discovered SVG Keylogger

Post by Tom T. »

GµårÐïåñ wrote:... Hence why people should beware on Chrome and such browsers WITHOUT NoScript.
Thank you for pointing that out. I'll add it to the "Chrome vs. Fx + NS" thread.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.25) Gecko/20111212 Firefox/3.6.25
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3369
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: Will NoScript stop recently discovered SVG Keylogger

Post by GµårÐïåñ »

Tom T. wrote:Thank you for pointing that out. I'll add it to the "Chrome vs. Fx + NS" thread.
:lol: Pile it on baby .... :P
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows NT 6.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Will NoScript stop recently discovered SVG Keylogger

Post by Tom T. »

I should have linked that thread for anyone watching this one.

http://forums.informaction.com/viewtopi ... =19&t=7727

My addition that you inspired.

And catch the one right above it, from info Giorgio linked to in the "NS Sightings" topic. :)
Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Post Reply