News: 1604062812

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Why, yes, you can register an XSS attack as a UK company name. How do we know that? Someone actually did it

(2020/10/30)


Companies House has blocked someone who registered a new biz with a name that contained the right characters arranged in the right order to trigger a cross-site scripting (XSS) attack against users of the service's API.

The company in question, registered number 12956509, was originally signed up with the UK's official company registrar under the name: " SCRIPT SRC[=]HTTPS[:]//MJT.XSS.HT LTD

Its name didn't contain the square brackets, meaning anyone reading company names off the [1]Companies House API would potentially run a script from the web address above.

A person using the username michaeltandy on the Companies House developer forum later [2]posted : "I had assumed I wouldn't be the first person to use < and > (they are, after all, both explicitly whitelisted as legal characters) and that 99 per cent of systems would already be escaping them... I would just get a company with a playful name that would elicit a knowing chuckle from the kind of people we'd be doing business with!"

The poster continued: "Once it turned out there were non-trivial problems, and that fact became more widely publicised, we can't expect every consumer of data to do a full XSS audit in only a few days."

Although whoever registered the company seems to have had non-hostile intentions – xss.ht is a domain owned by the XSS Hunter service, as explained on its main [3]website – the vulnerability it exposes is not unique.

Such tomfoolery has been carried out in the past, aided by a [4]legal requirement that certain punctuation marks are available for companies to use in their names. Thus was born " [5]; DROP TABLE "COMPANIES";-- LTD " and " [6]SAFDASD & SFSAF \' SFDAASF\" LTD ", both of which were exploiting the availability of punctuation marks to put commands into the company name field.

Tech lawyer Neil Brown of decoded.legal told The Register : "This is symbolic – if one might excuse the pun – of a regime which considers individual characters in isolation, and not the effect of the combination of those characters." He explained that while [7]section 53 of the Companies Act 2000 does stop people from registering companies with "offensive" names or names that were a criminal offence to publish, it's not clear whether that is enough to stop people registering database commands as company names.

"Would using an XSS attack constitute an offence? Even with the state of the Computer Misuse Act 1990, that would be a stretch too far. Is it offensive? I don't think so, but then I'm not the Secretary of State," opined Brown, who also pointed out [8]yet another crappy company name .

As for lessons to be drawn from this, Brown wondered if simply advising people to sanitise inputs from official systems was "too dull" for El Reg . We happen to agree but it's also the sort of common-sense advice someone, somewhere, might actually benefit from. The BBC Bitesize guide to input sanitisation (don't laugh, we all started somewhere) can be found [9]here .

A Companies House spokesman told The Register : "A company was registered using characters that could have presented a security risk to a limited number of our customers, if published on unprotected external websites. We have taken immediate steps to mitigate this risk."

He added: "We are confident that Companies House services remain secure."

And indeed Companies House is secure: company number 12956509 is [10]now called "THAT COMPANY WHOSE NAME USED TO CONTAIN HTML SCRIPT TAGS LTD". ®

Bootnotes

Drop Table Companies Ltd (add the necessary script marks at your leisure) was a practical joke by tech bod Sam Pizzey, who blogged about it [11]at the time . He wrote: "The company name is a bit of hacker sleight-of-hand... or as some astute people have put it, it's 'wrong'. Of course it's wrong – I'm not a total arsehole!"

Multiple people also [12]registered Openreach Ltd over the years until BT woke up and registered the company name itself.

Get our [13]Tech Resources



[1] https://developer.company-information.service.gov.uk/api/docs/index.html

[2] https://forum.aws.chdev.org/t/broken-company-name/3350

[3] https://xsshunter.com/features

[4] https://www.legislation.gov.uk/uksi/2015/17/schedule/1/made

[5] https://find-and-update.company-information.service.gov.uk/company/10542519

[6] https://find-and-update.company-information.service.gov.uk/company/08804157

[7] https://www.legislation.gov.uk/ukpga/2006/46/part/5/chapter/1

[8] https://find-and-update.company-information.service.gov.uk/search?q=12972728

[9] https://www.bbc.co.uk/bitesize/guides/z4cg4qt/revision/3

[10] https://find-and-update.company-information.service.gov.uk/company/12956509

[11] https://pizzey.me/blog/no-i-didnt-try-to-break-companies-house/

[12] https://find-and-update.company-information.service.gov.uk/company/10028016

[13] https://whitepapers.theregister.com/

Reminds me of Mr. Bastards.

Symon

"After being charged £20 for a £10 overdraft, 30 year old Michael Howard of Leeds changed his name by deed poll to 'Yorkshire Bank Plc are Fascist Bastards'. The bank has now asked him to close his account, and Mr Bastards has asked them to repay the 69p balance by cheque, made out in his new name."

Re: Reminds me of Mr. Bastards.

Triggerfish

After googling that i recommend reading the Guardian its a funny old world page that comes up in the google search.

https://www.theguardian.com/money/1999/nov/05/workandcareers1

We have taken immediate steps to mitigate this risk.

heyrick

Not really. You've taken steps to ensure it's not your fault. The risk is still there, in those external sites that don't sanitise inputs from {$WORLD}.

I am shocked and surprised: TFA failed to mention the "Obligatory XKCD"

cyberdemon

[1]Little Bobby Tables

[1] https://xkcd.com/327/

Re: I am shocked and surprised: TFA failed to mention the "Obligatory XKCD"

KittenHuffer

He was mentioned in one of the various links within the story.

It isn't actively policed

Dave314159ggggdffsdds

Companies Ho. doesn't actively police this sort of thing. It's triggered by complaints. Taking data from them without sanitising it is just plain stupid.

Notably, there are no restrictions whatsoever* on what can be registered as a company address. There is nothing stopping you naming your building (or business unit, office, etc) after Bobby Tables.

*Apart from those the Post Office has about addresses in general.

Years ago I went through a phase of adding the first line of address to mailing lists as 'The Bin'. I got junk mail for years after addressed to 'The Bin, 1 The Mall, SW1A 1AA'. (That's Buck House. Not my real address ;)

Re: It isn't actively policed

NerryTutkins

Cheeky. You should watch yourself in tunnels.

Re: It isn't actively policed

Robert Carnegie

Oh! Too soon. (....)

And if you are getting junk mail that is addressed to the royal family... are they getting yours? It would be polite to ask, next time you're over.

"there are no restrictions whatsoever"

Mike 137

The Business Names Act (and possibly other peripheral legislation) [1]restricts or prohibits certain choices of company name, but not on the grounds discussed in this piece. Mostly to protect government and infrastructure services or to avoid misrepresentation of scale or scope of businesses.

[1] https://www.gov.uk/government/publications/incorporation-and-names

Re: "there are no restrictions whatsoever"

Robert Carnegie

Does it qualify as misrepresenting the Company as executable program code?

Re: "there are no restrictions whatsoever"

stiine

What if the company /IS/ executable code?

Still winning

Anonymous Coward

Lol: the company name has been updated to the ascii code for the poop emoji

https://find-and-update.company-information.service.gov.uk/search?q=12972728

Re: Still winning

AW-S

Isn't that's a different company? 12956509 v 12972728

Good to see the Rev. up to his tricks.

Is it offensive?

I am the liquor

Surely an attack is by definition offensive.

Re: Is it offensive?

Phil O'Sophical

Or the best form of defence?

Re: Is it offensive?

I am the liquor

Why not both?

No, this computer is not for personal use - it's my woke one.

Brewster's Angle Grinder

That would be a creative blurring of meanings. But even a tech-phobic judge would struggle to imagine a computer becoming upset (entering an emotional state) upon reading a piece of gibberish. (Actually, that argument might have a better chance if the computer threw an exception - that's the best parallel to an upset human.)

You could maybe argue the name is deceptive. But the best bet might be for Randall Munroe to assert his copyright - then they might get in serious legal hotwater.

Re: No, this computer is not for personal use - it's my woke one.

JulieM

You aren't allowed a business name such that someone could commit a crime by uttering it aloud, so it would not be a massive stretch to block a business name that someone could commit an offence under the misuse of computers act by entering into a computer.

On the other hand, a Companies House employee entering a name into a Companies House computer in the course of their regular employment probably would not be unauthorised, so there still might not be any offence committed.

And if we do end up with a new law to prevent this, it's almost certain to be unfit for purpose .....

NullNix

So I saw the 'crappy company name' and had a look. Registered in Bracknell, oh, wait, this is RevK isn't it? Look over at 'People', and yes, it is.

See https://twitter.com/TheRealRevK/status/1319869941819101186

Anonymous Coward

Using a residential postal address, which following a recent policy change by Companies House, can never be removed from the public record, even after the Company is dissolved.

stiine

So? Can't he move?

"a limited number of our customers"

Anonymous Coward

You know you are talking to a PR bod when the number is always "limited".

And they're not lying: the "limit" could be arbitrarily large.

Re: "a limited number of our customers"

Anonymous Coward

More precisely, you know you're talking to a not very good PR bod. Qualifying everything as "limited" has become a bit tired by now and its only effect is to make your announcement look non-credible and evasive.

The cow is nothing but a machine which makes grass fit for us people to eat.
-- John McNulty