Clickjacking screenshot taker leads to cross origin info disclosure
Categories
(Firefox :: Screenshots, defect)
Tracking
()
People
(Reporter: qab, Unassigned)
References
(Depends on 1 open bug)
Details
(Keywords: sec-moderate)
Attachments
(3 files)
Reporter | ||
Comment 1•7 years ago
|
||
Comment 2•7 years ago
|
||
Reporter | ||
Comment 3•7 years ago
|
||
Comment 4•7 years ago
|
||
Updated•7 years ago
|
Comment 5•7 years ago
|
||
Comment 6•7 years ago
|
||
Comment 7•7 years ago
|
||
Reporter | ||
Comment 8•6 years ago
|
||
Updated•6 years ago
|
Comment 9•6 years ago
|
||
(In reply to Barry Chen from comment #7)
Ian filed https://github.com/mozilla-services/screenshots/issues/3508 and
has done some work on it. We should move it into the next sprint.
This has been closed because we're discontinuing server uploads in Firefox 67.
Does this mean this is fixed? Based on the descriptions here, I expect not, but I'd love to be wrong...
Comment 10•6 years ago
|
||
Hmm. Ian, what's the current timeline for screenshots?
Comment 11•5 years ago
|
||
(In reply to :Gijs (he/him) from comment #9)
This has been closed because we're discontinuing server uploads in Firefox 67.
Does this mean this is fixed? Based on the descriptions here, I expect not, but I'd love to be wrong...
It appears to be fixed. The shots UI can still be clickjacked (bug 1389707) but the clever extra bit here of stealing the image contents relied on having the shot URL in the page context which we no longer need to do since we don't upload it. Yes, this screenshotted the attacker's own page, but it could contain 3rd party images or frames that could be interesting to look at.
Updated•5 years ago
|
Updated•4 years ago
|
Updated•4 years ago
|
Description
•