News: 1592985072

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Three words do you not want to hear regarding a 'secure browser' called SafePay: Remote. Code. Execution

(2020/06/24)


Folks running Bitdefender's Total Security 2020 package should check they have the latest version installed following the disclosure of a remote code execution bug.

Wladimir Palant, cofounder of Adblock-Plus-maker Eyeo, tipped off Bitdefender about the flaw, [1]CVE-2020-8102 , which he found within the suite's SafePay "secure browser." Palant discovered what he called "seemingly small weaknesses" that could be exploited by a hostile website to take control over a computer when opened in Bitdefender's Chromium-based web browser. The bug, privately reported in April, was patched in May.

This week, Palant [2]said the vulnerability stems from the way SafePay – which is supposed to protect online payments from hackers – inspected HTTPS-encrypted connections for signs of malicious activity to block. To do this, the browser examined webpages and other data once it was fetched over HTTPS and decrypted.

"Occasionally their product will have to modify the server response, for example on search pages where they inject the script implementing the Safe Search functionality," Palant explained. "Here they unavoidably have to encrypt the modified server response with their own certificate."

This is where the software tripped up. When the software wanted to flag up suspicious or broken HTTPS certificates, which are sometimes a sign shenanigans may be afoot, Safepay generated a custom error page that appeared as though it came from the requested website. It would do this by modifying the server response.

It’s generally preferable that antivirus vendors stay away from encrypted connections as much as possible

There was nothing to stop a web server with a bad certificate from requesting the contents of Bitdefender's custom error page, though, because as far as the browser engine was concerned, the error page came from the web server anyway.

Thus, a malicious web server could serve a page with a good certificate, and cause a new window to open with a page from the same domain and server albeit with an invalid certificate. SafePay would jump in, and replace the second webpage with a custom error page. The first page with the good certificate could then use XMLHttpRequest to fetch the contents of the error page, which the browser would hand over.

That error page contained the Bitdefender installation's session tokens, which could be used to send system commands to the security software suite on the user's PC to execute. Palant's proof-of-concept exploit worked against a Windows host, allowing a malicious page to install, say, spyware or ransomware on a victim's computer.

"The URL in the browser’s address bar doesn’t change," Palant explained. "So as far as the browser is concerned, this error page originated at the web server and there is no reason why other web pages from the same server shouldn’t be able to access it. Whatever security tokens are contained within it, websites can read them out.

"It’s generally preferable that antivirus vendors stay away from encrypted connections as much as possible. Messing with server responses tends to cause issues even when executed carefully, which is why I consider browser extensions the preferable way of implementing online protection. But even with their current approach, Bitdefender should really leave error handling to the browser."

Bitdefender said the update to fix the hole should be [3]automatically applied.

"Improper input validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process," the biz acknowledged. "This issue affects Bitdefender Total Security 2020 versions prior to 24.0.20.116." ®

Sponsored: [4]Running Your Modern .NET Application on Kubernetes



[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8102

[2] https://palant.info/2020/06/22/exploiting-bitdefender-antivirus-rce-from-any-website/

[3] https://www.bitdefender.com/support/security-advisories/insufficient-url-sanitization-validation-safepay-browser-va-8631/

[4] https://go.theregister.com/tl/1956/-8477/running-your-modern-net-application-on-kubernetes?td=wptl1956

And that's how Marketing gets bitten

Pascal Monett

Bitdefender Total Security 2020 is not totally secure. Ironic.

Of course, from a marketing point of view, you couldn't call it Bitdefender Best Security Effort 2020. You are either Total, or you don't even exist.

Well, at least they corrected the problem when notified, not like some others on the market, eh, IBM ?

Re: And that's how Marketing gets bitten

Stuart Castle

Anyone who knows a fair bit about computer security knows that total security is almost impossible to achieve. Every security system has flaws, but to counter balance that, some flaws require a talented hacker to exploit. Thankfully, the chances are most users won't encounter a really talented hacker.

Re: And that's how Marketing gets bitten

vtcodger

Perhaps I misunderstand, but in this case, I think all that is necessary is for you to visit a website crafted by a really talented hacker. The website can promise to regrow hair, smooth out wrinkles, serve up free world class porn, earn you money at seven times the prime rate or to grant you eternal youth. It doesn't have to deliver any of those things.

Yet again ... yawn ...

Mike 137

'"Occasionally their product will have to modify the server response, for example on search pages where they inject the script implementing the Safe Search functionality," Palant explained.'

When will it finally sink in that client side scripting should never be used for security. Client side scripting is the primary vector for automatic client compromises, so it's the exact opposite of the right approach. If you want a secure browser, design one from the ground up in native code (or if you really must, an interpreted language like Java). That doesn't of course ensure it's not vulnerable, but it should be obvious that any code that sits within a web page is open to malicious tampering.

It gets late early out there.
-- Yogi Berra