{"id":86356,"date":"2020-06-24T13:42:00","date_gmt":"2020-06-24T11:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda"},"modified":"2020-06-24T13:42:00","modified_gmt":"2020-06-24T11:42:00","slug":"uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","title":{"rendered":"Vulnerability in the Bitdefender SafePay browser leading to code execution","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Vladimir Palant, creator of Adblock Plus, <noindex><a rel=\"nofollow\" href=\"https:\/\/palant.info\/2020\/06\/22\/exploiting-bitdefender-antivirus-rce-from-any-website\/\">identified<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.bitdefender.com\/support\/security-advisories\/insufficient-url-sanitization-validation-safepay-browser-va-8631\/\">vulnerability<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-8102\">CVE-2020-8102<\/a><\/noindex>) in the Chromium-based specialized web browser Safepay, offered as part of the Bitdefender Total Security 2020 antivirus package, aimed at enhancing user security while browsing the global network (for example, providing additional isolation when accessing banks and payment systems). The vulnerability allows websites opened in the browser to execute arbitrary code at the operating system level.<\/p>\n<p>The root of the problem is that the Bitdefender antivirus performs local interception of HTTPS traffic by substituting the original TLS certificate of the website. An additional root certificate is installed on the client\u2019s system, allowing the traffic inspection system to operate covertly. The antivirus injects its own JavaScript code into certain pages to implement the Safe Search feature, and in case of a problem with the secure connection certificate, it replaces the error page with its own. Since the new error page is presented on behalf of the opened server, other pages of this server have full access to the content injected by Bitdefender.<\/p>\n<p>When opening a website controlled by the attacker, this site can send an XMLHttpRequest and simulate an HTTPS certificate problem in the response, resulting in a page with an error modified by Bitdefender. Since the error page is opened within the context of the attacker's domain, they can read the content of the modified page with Bitdefender parameters. The Bitdefender page also contains a session key that allows launching a separate Safepay browser session using Bitdefender's internal API, specifying arbitrary command-line flags and achieving the execution of any system commands via the &#171;&#8212;utility-cmd-prefix&#187; flag. Example exploit (param1 and param2 are values obtained from the error page):<\/p>\n<p>   var request = new XMLHttpRequest();<br \/>\n   request.open(&#171;POST&#187;, Math.random());<br \/>\n   request.setRequestHeader(&#171;Content-type&#187;, &#171;application\/x-www-form-urlencoded&#187;);<br \/>\n   request.setRequestHeader(&#171;BDNDSS_B67EA559F21B487F861FDA8A44F01C50&#187;, param1);<br \/>\n   request.setRequestHeader(&#171;BDNDCA_BBACF84D61A04F9AA66019A14B035478&#187;, param2);<br \/>\n   request.setRequestHeader(&#171;BDNDWB_5056E556833D49C1AF4085CB254FC242&#187;, &#171;obk.run&#187;);<br \/>\n   request.setRequestHeader(&#171;BDNDOK_4E961A95B7B44CBCA1907D3D3643370D&#187;, location.href);<br \/>\n   request.send(&#171;data:text\/html,nada &#8212;utility-cmd-prefix=&#092;&#187;cmd.exe \/k whoami &#038; echo&#092;&#187;&#187;);<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/palant.info\/2020\/06\/22\/exploiting-bitdefender-antivirus-rce-from-any-website\/rce.png\"><img decoding=\"async\" alt=\"Vulnerability in the Bitdefender SafePay browser leading to code execution\" src=\"\/wp-content\/uploads\/2020\/06\/63506c8918fac4714433bbb539926777.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Recall that a study conducted in 2017  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=45996\">showed<\/a><\/noindex>, found that 24 out of 26 tested antivirus products, inspecting HTTPS traffic through certificate substitution, reduced the overall security level of HTTPS connections.<br \/>\nCurrent cipher suites were provided only in 11 out of 26 products. 5 systems did not perform certificate verification (Kaspersky Internet Security 16 Mac, NOD32 AV 9, CYBERsitter, Net Nanny 7 Win, Net Nanny 7 Mac). Kaspersky Internet Security and Total Security products were vulnerable to attacks <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=34869\">CRIME<\/a><\/noindex>, while AVG, Bitdefender and Bullguard products were susceptible to attacks <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=42270\">Logjam<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=40833\">POODLE<\/a><\/noindex>. Dr.Web Antivirus 11 allows reverting to insecure export ciphers (attack <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=41782\">FREAK<\/a><\/noindex>).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53223\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-8102) \u0432 \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0430 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c web-\u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 Safepay, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u043e\u0433\u043e \u043f\u0430\u043a\u0435\u0442\u0430 Bitdefender Total Security 2020 \u0438 \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u043c \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0432 \u0433\u043b\u043e\u0431\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u0430\u044f \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u043a \u0431\u0430\u043d\u043a\u0430\u043c \u0438 \u043f\u043b\u0430\u0442\u0451\u0436\u043d\u044b\u043c \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c\u044b\u043c \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 \u0441\u0430\u0439\u0442\u0430\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":86357,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-86356","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u043c \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 Bitdefender SafePay, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-24T11:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-24T11:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47A vulnerability in the secure browser Bitdefender SafePay that leads to code execution | ProHoster","description":"Vladimir Palant, the creator of Adblock Plus, discovered","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u043c \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 Bitdefender SafePay, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster","og:description":"\u0412\u043b\u0430\u0434\u0438\u043c\u0438\u0440 \u041f\u0430\u043b\u0430\u043d\u0442, \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c Adblock Plus, \u0432\u044b\u044f\u0432\u0438\u043b","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-zashhishhyonnom-brauzere-bitdefender-safepay-privodyashhaya-k-vypolneniyu-koda","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-24T11:42:00+00:00","article:modified_time":"2020-06-24T11:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"86356","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:17:32","updated":"2022-09-28 12:42:50","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/86356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=86356"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/86356\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/86357"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=86356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=86356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=86356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}