A recent CNET article http://download.cnet.com/8301-2007_4-57 ... ?tag=mncol
about a Keylogger attack via a browser SVG flaw mentions NoScript but seems to indicate that NoScript would not stop this.
I have "Block every object coming from a site marked as untrusted" checked. Wouldn't this prevent SVG objects?
Will NoScript stop recently discovered SVG Keylogger
Will NoScript stop recently discovered SVG Keylogger
Last edited by mcgyver5 on Fri Jan 06, 2012 9:58 pm, edited 2 times in total.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Re: Will NoScript stop recently discovered SVG Keylogger
Looks like the board mangled the link.
Lets see if this sticks ...
Keylogging threat could lead to more attacks, say researchers
or
http://download.cnet.com/8301-2007_4-57353483-12/keylogging-threat-could-lead-to-more-attacks-say-researchers/
Yep.
And yep again.
Lets see if this sticks ...
Keylogging threat could lead to more attacks, say researchers
or
http://download.cnet.com/8301-2007_4-57353483-12/keylogging-threat-could-lead-to-more-attacks-say-researchers/
Yep.
And yep again.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:11.0a2) Gecko/20120105 Firefox/11.0a2 SeaMonkey/2.8a2
Re: Will NoScript stop recently discovered SVG Keylogger
Interesting.
At present, you've got to think that for the average badguy, JavaScript is just too easy to go scriptless.
In any case, you know scriptless will come, just a matter of time & cost/benefit to the badguys.
If NoScript blocks SVG (don't know if it does?), if SVG is considered an Embedding, where Forbid other plugins would cover it, then you could be protected in that respect?
And if done, then it makes the web far more dangerous."The basic premise of my research currently is scriptless attacks, meaning attack vectors working in a post-XSS world," Heiderich said in an e-mail. He defined a "post-XSS" world as one where the cross-site scripting attack had been more or less minimized by technologies like sandboxed iFrames, Mozilla's e-mail client Thunderbird and Firefox's Content Security Policy, the JavaScript blocking browser add-on NoScript, and Windows 8.
At present, you've got to think that for the average badguy, JavaScript is just too easy to go scriptless.
In any case, you know scriptless will come, just a matter of time & cost/benefit to the badguys.
If NoScript blocks SVG (don't know if it does?), if SVG is considered an Embedding, where Forbid other plugins would cover it, then you could be protected in that respect?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:11.0a2) Gecko/20120105 Firefox/11.0a2 SeaMonkey/2.8a2
Re: Will NoScript stop recently discovered SVG Keylogger
thanks, I fixed the link. When I check "Block Every object coming from a site marked as untrusted", all SVG elements on pages are blocked, as far as I can tell...
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Will NoScript stop recently discovered SVG Keylogger
NoScript has been providing specific protection against this kind of attack since before it was revealed:
Code: Select all
v 2.2.2rc1
==========================================================================
+ [XSS] Explicit check for potentially dangerous SMIL elements (thanks
.mario for suggestion)
+ Protection against scriptless keylogging (thanks .mario for reporting)
Mozilla/5.0 (Windows NT 5.2; WOW64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3369
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: Will NoScript stop recently discovered SVG Keylogger
As Giorgio already pointed out, this is already moot and has been for a while. Unless a POC showing currently it can defeat NS, we are in the clear. Hence why people should beware on Chrome and such browsers WITHOUT NoScript.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows NT 6.1; rv:8.0) Gecko/20100101 Firefox/8.0
Re: Will NoScript stop recently discovered SVG Keylogger
Thank you for pointing that out. I'll add it to the "Chrome vs. Fx + NS" thread.GµårÐïåñ wrote:... Hence why people should beware on Chrome and such browsers WITHOUT NoScript.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.25) Gecko/20111212 Firefox/3.6.25
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3369
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: Will NoScript stop recently discovered SVG Keylogger
Tom T. wrote:Thank you for pointing that out. I'll add it to the "Chrome vs. Fx + NS" thread.


~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows NT 6.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Re: Will NoScript stop recently discovered SVG Keylogger
I should have linked that thread for anyone watching this one.
http://forums.informaction.com/viewtopi ... =19&t=7727
My addition that you inspired.
And catch the one right above it, from info Giorgio linked to in the "NS Sightings" topic.
http://forums.informaction.com/viewtopi ... =19&t=7727
My addition that you inspired.
And catch the one right above it, from info Giorgio linked to in the "NS Sightings" topic.

Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1