Vulnerability in Adblock Plus allows code execution when using questionable filters

In the Adblock Plus ad blocker identified a vulnerability, which allows allows the execution of JavaScript code in the context of websites when using unverified filters prepared by attackers (for example, when connecting third-party rule sets or through rule substitution during a MITM attack).

The authors of filter sets can arrange for their code to execute within the context of websites opened by the user by adding rules with the operator "rewrite" that allows part of the URL to be replaced. The rewrite operator does not allow replacing the host in the URL but enables manipulation of query parameters. Only text can be used as a mask for replacement, while the insertion of script, object, and subdocument tags Imagine that all the resources you currently use are blocked. You are left with only those that are not forbidden. Chinese IT companies started to grow wildly, creating local equivalents of Western services:.

However, code execution can be achieved through an indirect method.
Some websites, including Google Maps, Gmail, and Google Images, use the technique of dynamically loading executable JavaScript blocks, transmitted in plain text. If the server allows request redirection, it is possible to redirect to another host by modifying URL parameters (for example, in the context of Google, a redirect can be made through the API "google.com/search"). Besides hosts that allow redirection, an attack can also be directed against services that allow user content placement (code hosting, article hosting platforms, etc.).

The proposed attack method affects only pages that dynamically load lines with JavaScript code (for example, via XMLHttpRequest or Fetch) and then execute them. Another important limitation is the necessity of using redirection or placing arbitrary data on the original server that delivers the resource. Nevertheless, to illustrate the relevance of the attack, it is shown how to organize code execution when opening maps.google.com, using a redirect through "google.com/search".

A fix is still being prepared. The issue also affects blockers AdBlock and uBlock. The uBlock Origin blocker is not vulnerable to this issue as it does not support the rewrite operator. In the past, the author of uBlock Origin
refused add support for rewrite, citing potential security issues and insufficient host-level restrictions (instead of rewrite, the option querystrip was suggested to clean request parameters instead of replacing them).

The developers of Adblock Plus consider real attacks to be unlikely as all changes to standard rule lists undergo review, and the use of third-party lists is extremely rare among users. The replacement of rules via MITM is excluded by the default application of HTTPS for loading standard blocking lists (loading via HTTP is planned to be banned for other lists in a future release). Directives can be used to block attacks on the site side. CSP (Content Security Policy), through which hosts can be explicitly defined from which the loading of external resources is permitted.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster