Monday, July 26, 2010

Google on browser and plugin attacks and defenses

Chris Evans of Google presented a talk on browser and plugin attacks. Ian Fette (also of Google) talked about the blacklisting approach and its value in browser security in the same talk (at 30:00).

Some interesting highlights:
  • The plugin distribution for users of Chrome v4.1 is shared:
    • 97%: Flash
    • 86%: Adobe Reader
    • 66%: Java (only 14% were fully uptodate)
    • 53%: Windows Media Player
    • 49%: Silverlight Plug-in
    • 39%: Quicktime Plug-in
  • The speaker has most of his plugins disabled, to reduce the vulnerability surface in his browser -- he recommends the same for users.
  • Websites can request an old version of Java to be installed on the fly, basically allowing websites to put security holes in your system that you did not have. Java is so powerful that it's essentially impossible to sandbox, and its cross-platform capabilities means you can write an exploit once, and it will work on every OS. Only 14% of users were fully up-to-date with Java.
  • All browsers are working on various defenses against these attacks, including sandboxing, warning about out-of-date plugins, or bundling some plugins so they can auto-update them. Ian talks extensively about the blacklist approaches (such as Google Safe Browsing on Firefox, Safari and Chrome, and SmartScreen Filter for IE8) to mitigate against zero-days, and social engineering malware.
  • There's approximately 500,000 URLs in the Google Safe Browsing lists at any time, and the lists are delivered to hundreds of millions of users.
  • About 50% of users ignore the phishing or malware warnings on Chrome, even though Google has very high confidence when it adds something on the lists, since it uses virtual machines to verify eg malicious websites.

Full video here

Friday, July 16, 2010

SecBrowsing becoming an official part of Chrome

Last month the Chrome team announced a number of security features regarding plug-ins, including the integration of the SecBrowsing features in the browser.  Here's the relevant snippet from the blog post (http://blog.chromium.org/2010/06/improving-plug-in-security.html): 
Protection from out-of-date plug-ins: Medium-term, Google Chrome will start refusing to run certain out-of-date plug-ins (and help the user update).
The blog post enumerates all the current and upcoming security features in Chrome regarding plugins: 
  • More powerful plug-in controls
  • Autoupdate for Adobe Flash Player
  • Integrated, sandboxed PDF viewing
  • Protection from out-of-date plug-ins
  • Warning before running infrequently used plug-ins
  • A next generation plug-in API
As of Chrome v6.0.466.0 (developer channel as of July 15, 2010), SecBrowsing is partly integrated in Chrome. In "about:plugins", any plugins missing security updates are shown with a warning and a link to get the latest version. There is no active warning anywhere yet, but that's definitely coming up soon.

Saturday, June 19, 2010

Beyond SecBrowsing with Secunia

I've tested Secunia PSI, a free vulnerable software manager. I recommend it.

What is Secunia
It extends beyond SecBrowsing's checks for out-of-date browser plugins, and identifies known vulnerabilities in software such as media players, office, IM, Skype, and other  applications that don't run in your browser.

Why
Malicious attachments, sent over email or IM, can attack your applications. Vulnerabilities in internet-connected apps such as IM clients or Skype may allow attackers to install malware on your machine without any interaction. You really don't want to run applications with known security holes on your machine.

A review
Last week I had the chance to try it out on a PC. It took a while to scan the machine (see say about 5 minutes) but it identified various software that were unpatched, such as OpenOffice, Skype and VLC. In an ideal world, Secunia would also update this software for me. Or Windows! Anyway, it looks like something is in the works already for this.

I was glad (and kind of surprised actually) to see that as soon as I was able to update a certain application, secunia picked it up immediately and even notified me that it was now up-to-date. On the downside, it took me a lot of time and effort to update all the software.

Take OpenOffice, for example. Secunia says it's unpatched, what next? Start -> Programs -> OpenOffice ... I see apps like Writer, Spreadsheets, but no "updater" or anything. I took an educated guess and opened one of the applications (Writer). Help -> Check for Updates ... yes, that's it. 20 minutes later or so it has downloaded and installed the new version. Why so slow!

In any case, Secunia also has links to their forum, I'm sure they explain how to update your applications. Or maybe you can Google it. Auto-update sure sounds exciting.

I installed Secunia on my brother's machine, hoping he will act upon the warnings. I told my father to install it too, but I really really doubt he can act upon the warnings. It all boils down to automatic, silent updates. This should be the responsibility of the Operating System (Ubuntu, Android, iPhone OS all do this, to a certain degree), but not OS X or Windows, which makes third-party apps such as Secunia essential.

So Windows users, try out Secunia.

Thursday, June 17, 2010

Latest Chrome brings sandboxed, auto-updated PDF support

With the latest Chrome version (developer channel for Windows and Mac for now: http://dev.chromium.org/getting-involved/dev-channel) Chrome provides native support for rendering PDF documents in a seamless, and more importantly, secure way: http://blog.chromium.org/2010/06/bringing-improved-pdf-support-to-google.html


According to the blogpost, PDF rendering will be contained within the security sandbox Chrome uses for web page rendering. Users will automatically receive the latest version of Chrome’s PDF support; they won’t have to worry about manually updating any plug-ins or programs.

The plug-in can be enabled by going to chrome://plugins/ and clicking on "Enable" for the "Chrome PDF Viewer" plug-in. While you are at it, I would recommend you disable any other PDF plugins.

Friday, June 11, 2010

Quicktime warnings on Mac Snow Leopard (10.6)

Executive summary: If you have Snow Leopard and Quicktime < 7.6.6, upgrade your OS to 10.6.3.

We've had quite a few reports on our extension homepage about Quicktime X, which is available only for Mac OS 10.6, and its incompatibility with Quicktime 7. The solution we offer (a link to download the latest version of Quicktime) is problematic.

A user reports:
Secbrowsing keeps telling me that I need to update my quicktime plugin for 7.6.3 to 7.6.4 though 7.6.4 is not available for my operating system OSX 10.6 (Snow Leopard).
One of our users has even shared a screenshot with us:



There's very little documentation about this on the web, so I thought I'd write something down about potential workarounds.

It seems like in 10.6.3, Quicktime 7 (and X) is bundled with the OS. This creates confusion when there's a security fix for Quicktime 7, but no apparent way to get the new version in OS 10.6.

I have not investigated previous security fixes (7.6.4, 7.6.5), but I have investigated 7.6.6:

The security fixes in 7.6.6 also went into the security fix for Snow Leopard: 10.6.3 http://support.apple.com/kb/HT4077. I've also verified that a newly bought 10.6 laptop reports "Quicktime 7.6.6" as a plugin in Chrome and Firefox. So if you have 7.6.5 or 7.6.3 or earlier on Snow Leopard, you can only get 7.6.6 by installing the Snow Leopard security updates.

Thursday, June 10, 2010

Security Update: Flash 10.1 r53

http://secbrowsing.appspot.com/ was just updated to point to version 10.1 r53, which fixes several critical security vulnerabilies.

Saturday, May 15, 2010

How to update / disable / uninstall Shockwave for Director

On Aug 24, 2010 a new set of critical vulnerabilities was fixed for Shockwave for Director. [http://www.adobe.com/support/security/bulletins/apsb10-20.html].
To Update Shockwave for Director:
  • You can download the latest version at http://get.adobe.com/shockwave/
  • The latest version is 11.5.8, and SecBrowsing can now detect this version accurately.
To disable Shockwave for Director:
On all platforms, in Google Chrome, you can disable the plugin:
  • Type "about:plugins" (without the quotes) in your browser window
  • Click "disable" on the plugin named "Adobe Shockwave for Director" (not Flash)
To uninstall Shockwave for Director:
Windows:
  • Control Panel
  • Add/Remove Programs
  • Find Shockwave for Director (not Flash) and uninstall it. If you have an "ActiveX" and a "plugin" it's because they ship two different products, one for IE and one for Firefox/Chrome, so remove them both.
Mac:
  • The installer also contains the uninstaller: 
  • Save the uninstaller to your desktop and launch it (Shockwave_Uninstaller)
Some common questions I get asked about Shockwave:
  • Do I have Shockwave for Director?
    • Probably. According to Adobe, over "450 million desktops have installed Adobe Shockwave Player".
  • Shockwave is the same Flash? 
    • No. Adobe Flash is what we all know as Flash. Adobe Shockwave Player or Shockwave for Director is something else - completely unrelated.
  • If I uninstall Shockwave, will my browsing experience be affected?
    • Probably not, for the most part. See the discussion below from users who list a few sites that require Shockwave.
  • Why does SecBrowsing keep telling me my Shockwave is out of date? I'm sure I just updated it.
    • This is no longer the case as of 11.5.8. Please restart your browser, and the warning will go away.

      Friday, April 23, 2010

      Providing Warnings for Adobe Acrobat

      We've recently started tracking version information for Adobe Reader. Versions before 9.3.2 did not export their version number so it was difficult to tell if the installed plugin was out-of-date or not. This means that if you're running a version of Reader older than 9.3.2 and using our Chrome Extension, you'll see an out-of-date message.

      As mentioned in a previous post, older versions of Adobe Reader have critical security problems. Please download and install the newest version from http://get.adobe.com/reader. Note that you may need to launch Reader and run the Updater manually to force the upgrade from 9.3.0 to 9.3.2.

      Friday, April 16, 2010

      New Security Problems in Adobe Reader, new version.

      According to a new security bulletin by Adobethere's critical security problems in Adobe Reader, and you should update immediately to Adobe Reader 9.3.2 or 8.2.2


      Adobe Reader users on Windows can also find the appropriate update here:
      http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows.

      Adobe Reader users on Macintosh can also find the appropriate update here:
      http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh.

      Adobe Reader users on UNIX can find the appropriate update here:
      http://get.adobe.com/reader/.

      A Java vulnerability & update

      Yesterday, Oracle announced a new update for Java which fixes the serious vulnerabilities announced earlier this month. All Java versions prior to version 6 U20 are vulnerable and are being exploited in the wild.

      Friday, April 2, 2010

      New QuickTime and Java vulnerabilities & updates

      Yesterday, Apple announced multiple vulnerabilities in QuickTime and provided a new update (7.6.6).  This update fixes vulnerabilities which, "may lead to an unexpected application termination or arbitrary code execution". For more information see Apple's announcement: http://support.apple.com/kb/HT4104.

      Java also announced that they found and fixed 27 new security related bugs in their newest version of Java (6 U19). From Oracle's website: "Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible. This Critical Patch Update contains 27 new security fixes across all products.". For more information see: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html

      We have updated SecBrowsing to warn users that run earlier, vulnerable versions of QuickTime and Java plugins in their browser.

      Thursday, March 11, 2010

      How to disable plugins in Chrome

      Disable specific plugins
      1. Type "about:plugins" in the address bar of Chrome, and hit enter.
      2. In the list of plugins that appears, disable the ones you don't recognize and need. 

      [Advanced] Disable all plugins, and allow specific sites only
      1. Click the Tools (wrench) menu.
      2. Options.
      3. Under the Hood.
      4. Content settings in the "Privacy" section.
      5. Plug-ins tab.
      6. Select "Do not allow any site to use plug-ins." You can make exceptions for specific websites by clicking Exceptions.
      7. Click Close to save your setting.

        Thursday, February 18, 2010

        New Adobe Reader vulnerability, open Adobe Reader -> Help -> Update.

        Quoting http://www.adobe.com/support/security/bulletins/apsb10-07.html

        A critical vulnerability has been identified in Adobe Reader 9.3 and Acrobat 9.3 for Windows, Macintosh and UNIX, [...] As described in Security Bulletin APSB10-06, this vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests. In addition, a critical vulnerability (CVE-2010-0188) has been identified that could cause the application to crash and could potentially allow an attacker to take control of the affected system.

        Adobe recommends users [...] update to Adobe Reader 9.3.1.

        Note that this allows any website you visit to take over your machine, it's not required that you eg open a bad PDF file that was emailed to you, websites embed evil PDFs all the time (especially hacked websites).

        SecBrowsing does not track Adobe Reader yet because its version is not exposed in the browser. So please go ahead and update Adobe Reader manually:
        • Launch Adobe Reader
        • Help
        • Check for Updates

        Thursday, February 11, 2010

        New Flash player vulnerability, v10.0.45.2 released

        Quoting Adobe Security Bulletin,
        a critical vulnerability has been identified in Adobe Flash Player version 10.0.42.34 and earlier. This vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests.
        Adobe recommends users of Adobe Flash Player 10.0.42.34 and earlier versions update to Adobe Flash Player 10.0.45.2

        I think this translates to "any website with a malicious flash object can make requests to websites with private information such as email, bank accounts etc". I might be wrong. But unauthorized cross-domain requests are not good. At least the vulnerability does not allow arbitrary code execution, but these days, if you can take over the browser, you are almost as good as taking over the machine itself.

        Secbrowsing points to version 10.0.45.2.

        Friday, February 5, 2010

        New Chrome extension hides the icon if all is good.

        The most requested feature for our Chrome extension was to hide the icon if all was good. Today Noe pushed a version of the extension that does that. The icon moved from the toolbar inside the address bar. It's a bit less visible, but it does not take up valuable space if you are up-to-date.

        Important: If you don't see any icon, do not worry: You are up-to-date.
        If you want to verify that SecBrowsing is installed, click wrench > Extensions.



        Here's how it will look like if your have an out-of-date plugin:


        As always, click on the red icon to get to http://secbrowsing.appspot.com/ with directions on how to update your plugins.

        Better plugin version detection thanks to Firefox 3.6

        Up until a few days ago, in order to find and parse plugin versions in JavaScript one had to write a pretty complex function that also involved a lot of guesswork, as you can see in our source code.

        As of Firefox 3.6, however, websites can access the plugin version in the simplest way possible:
        navigator.plugins[i].version
        This means SecBrowsing can use this version when available and correctly detect plugins we cannot detect now correctly, such as

        • Adobe Reader
        • Shockwave for Director
        • RealPlayer 
        We can also try to get this functionality into Google Chrome, so SecBrowsing can be accurate for Chrome as well. Stay tuned.

        Thursday, February 4, 2010

        New Internet Explorer security vulnerability

        IE uses, you should visit this link and update your security settings http://www.microsoft.com/technet/security/advisory/980088.mspx

        From the bulletin:
        Our investigation so far has shown that if a user is using a version of Internet Explorer that is not running in Protected Mode an attacker may be able to access files with an already known filename and location.
        Which means, for example, that if you can figure out the user's user name, you can read their address book from your website: "C:\Documents and Settings\user_name\Application Data\Microsoft\Address Book\user_name.wab".

        Saturday, January 30, 2010

        Take a second and disable Javascript from Acrobat Reader

        Secbrowsing does not yet track the versions of the Adobe Reader plugin, because Reader does not expose its version to websites. We plan to find a way to track the version soon. In the meantime, please:
        • Update Acrobat Reader
        • Disable Acrobat Javascript
        Update Acrobat Reader
        1. Launch Adobe Reader
        2. Select Help > Check for Updates
        3. Exit Adobe Reader
        4. Repeat
        You might have to repeat this process a few times if you have missed a lot of updates. Keep asking Reader to check for updates, even after it has installed some. If you have 9.1.1 and the latest version is 9.1.3 you need to run the update process twice.

        Disable Acrobat Javascript

        Also, please disable JavaScript for Reader. Many of the security releases of Reader fix vulnerabilities that involve its JavaScript engine.
        1. Launch Acrobat or Adobe Reader.
        2. Select Edit > Preferences
        3. Select the JavaScript Category
        4. Uncheck the 'Enable Acrobat JavaScript' option
        5. Click OK
        More about disabling Javascript, from Adobe. HowtoGeek also has a screenshot.

        Sunday, January 24, 2010

        Check your plugins right within iGoogle

        Aiming for the smallest iGoogle gadget ever (in terms of screen real estate), today we made SecBrowsing available for your iGoogle homepage:



        Go ahead and add it to your Google homepage