{"id":31710,"date":"2019-10-31T21:42:39","date_gmt":"2019-10-31T18:42:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-adblock-plus-pozvolyayushhaya-vypolnit-kod-pri-ispolzovanii-somnitelnyh-filtrov\/"},"modified":"2019-10-31T21:42:39","modified_gmt":"2019-10-31T18:42:39","slug":"uyazvimost-v-adblock-plus-pozvolyayushhaya-vypolnit-kod-pri-ispolzovanii-somnitelnyh-filtrov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-adblock-plus-pozvolyayushhaya-vypolnit-kod-pri-ispolzovanii-somnitelnyh-filtrov","title":{"rendered":"Vulnerability in Adblock Plus allows code execution when using questionable filters","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In the Adblock Plus ad blocker <noindex><a rel=\"nofollow\" href=\"https:\/\/adblockplus.org\/blog\/potential-vulnerability-through-the-url-rewrite-filter-option\">identified<\/a><\/noindex> a vulnerability, <noindex><a rel=\"nofollow\" href=\"https:\/\/armin.dev\/blog\/2019\/04\/adblock-plus-code-injection\/\">which allows<\/a><\/noindex> allows the execution of JavaScript code in the context of websites when using unverified filters prepared by attackers (for example, when connecting third-party rule sets or through rule substitution during a MITM attack).<\/p>\n<p>Authors of lists with filter sets can organize the execution of their code in the context of the websites opened by users by adding rules with the operator &#171;<noindex><a rel=\"nofollow\" href=\"https:\/\/help.eyeo.com\/en\/adblockplus\/how-to-write-filters#rewrite\">rewrite<\/a><\/noindex>&#171;, which allows replacing part of the URL. The rewrite operator does not allow replacing the host in the URL, but it enables free manipulation of query arguments. Only plain text can be used as a mask for replacement, and the insertion of script, object, and subdocument tags is not permitted. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/adblockplus\/adblockpluscore\/blob\/247943b2fa3464521bfee90edcbba5e64d29434e\/lib\/filterClasses.js#L1076\">Imagine that all the resources you currently use are blocked. You are left with only those that are not forbidden. Chinese IT companies started to grow wildly, creating local equivalents of Western services:<\/a><\/noindex>. <\/p>\n<p>However, code execution can be achieved through an indirect method.<br \/>\nSome websites, including Google Maps, Gmail, and Google Images, use the technique of dynamic loading of executable JavaScript blocks transmitted in plain text. If the server allows request redirection, it is possible to achieve redirection to another host by substituting URL parameters (for example, in the context of Google, the redirect can be performed through the API &#171;<noindex><a rel=\"nofollow\" href=\"https:\/\/www.google.com\/search?hl=en-US&#038;source=hp&#038;biw=&#038;bih=&#038;q=majestic-ramsons.herokuapp.com&#038;btnI=I%27m+Feeling+Lucky&#038;gbv=1\">google.com\/search<\/a><\/noindex>&#171;). Besides hosts that allow redirection, an attack can also be carried out against services that allow user-generated content placement (code hosting, article hosting platforms, etc.).<\/p>\n<p>The proposed attack method only affects pages that dynamically load lines with JavaScript code (for example, via XMLHttpRequest or Fetch) and then execute it. Another important limitation is the necessity of using redirection or placing arbitrary data on the side of the originating server serving the resource. However, as a demonstration of the attack's relevance, it is shown how to organize the execution of one's code when opening maps.google.com, using redirection through &#171;google.com\/search&#187;.<\/p>\n<p>A fix is still being prepared. The issue also affects blockers  <noindex><a rel=\"nofollow\" href=\"https:\/\/getadblock.com\/\">AdBlock<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ublock.org\/\">uBlock<\/a><\/noindex>The uBlock Origin blocker is not susceptible to this issue, as it does not support the &#171;rewrite&#187; operator. In due time, the author of uBlock Origin.<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/uBlockOrigin\/uBlock-issues\/issues\/46#issuecomment-391303700\">refused<\/a><\/noindex> add support for rewrite, citing potential security issues and insufficient host-level restrictions (instead of rewrite, the option querystrip was suggested to clean request parameters instead of replacing them).<\/p>\n<p>The developers of Adblock Plus consider real attacks to be unlikely as all changes to standard rule lists undergo review, and the use of third-party lists is extremely rare among users. The replacement of rules via MITM is excluded by the default application of HTTPS for loading standard blocking lists (loading via HTTP is planned to be banned for other lists in a future release). Directives can be used to block attacks on the site side. <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Content_Security_Policy\">CSP<\/a><\/noindex> (Content Security Policy), through which hosts can be explicitly defined from which the loading of external resources is permitted. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50521\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u0435 \u0440\u0435\u043a\u043b\u0430\u043c\u044b Adblock Plus \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 JavaScript-\u043a\u043e\u0434\u0430 \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u0441\u0430\u0439\u0442\u043e\u0432, \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043d\u0435\u043f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043d\u044b\u0445 \u0444\u0438\u043b\u044c\u0442\u0440\u043e\u0432, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430\u043c\u0438 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u0440\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u0445 \u043d\u0430\u0431\u043e\u0440\u043e\u0432 \u043f\u0440\u0430\u0432\u0438\u043b \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 \u043f\u043e\u0434\u043c\u0435\u043d\u0443 \u043f\u0440\u0430\u0432\u0438\u043b \u0432 \u0445\u043e\u0434\u0435 MITM-\u0430\u0442\u0430\u043a\u0438). \u0410\u0432\u0442\u043e\u0440\u044b \u0441\u043f\u0438\u0441\u043a\u043e\u0432 \u0441 \u043d\u0430\u0431\u043e\u0440\u0430\u043c\u0438 \u0444\u0438\u043b\u044c\u0442\u0440\u043e\u0432 \u043c\u043e\u0433\u0443\u0442 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c \u0441\u0430\u0439\u0442\u043e\u0432 \u0447\u0435\u0440\u0435\u0437 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b \u0441 \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u043e\u043c &#171;rewrite&#171;, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-31710","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u0435 \u0440\u0435\u043a\u043b\u0430\u043c\u044b Adblock Plus \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-adblock-plus-pozvolyayushhaya-vypolnit-kod-pri-ispolzovanii-somnitelnyh-filtrov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Adblock Plus, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0441\u043e\u043c\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u0444\u0438\u043b\u044c\u0442\u0440\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u0435 \u0440\u0435\u043a\u043b\u0430\u043c\u044b Adblock Plus \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-adblock-plus-pozvolyayushhaya-vypolnit-kod-pri-ispolzovanii-somnitelnyh-filtrov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:42:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:42:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in Adblock Plus allowing code execution when using questionable filters | ProHoster","description":"A vulnerability has been identified in the Adblock Plus ad blocker,","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-adblock-plus-pozvolyayushhaya-vypolnit-kod-pri-ispolzovanii-somnitelnyh-filtrov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Adblock Plus, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0441\u043e\u043c\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u0444\u0438\u043b\u044c\u0442\u0440\u043e\u0432 | ProHoster","og:description":"\u0412 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u0435 \u0440\u0435\u043a\u043b\u0430\u043c\u044b Adblock Plus \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c,","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-adblock-plus-pozvolyayushhaya-vypolnit-kod-pri-ispolzovanii-somnitelnyh-filtrov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:42:39+00:00","article:modified_time":"2019-10-31T18:42:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31710","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 07:28:06","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:12:33","updated":"2026-01-21 07:28:06","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=31710"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31710\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=31710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=31710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=31710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}