Thousands of Firefox users accidentally commit login cookies on GitHub
- Reference: 1637265870
- News link: https://www.theregister.co.uk/2021/11/18/firefox_cookies_github/
- Source link:
These [1]cookies.sqlite databases normally reside in the [2]Firefox profiles folder. They're used to store cookies between browsing sessions. And they're findable by searching GitHub with specific query parameters, what's known as a search "dork."
Aidan Marlin, a security engineer at London-based rail travel service Trainline, alerted The Register to the public availability of these files after reporting his findings through HackerOne and being told by a GitHub representative that "credentials exposed by our users are not in scope for our Bug Bounty program."
[3]
Marlin then asked whether he could make his findings public and was told he's free to do so.
[4]
[5]
"I'm frustrated that GitHub isn't taking its users' security and privacy seriously," Marlin told The Register in an email. "The least it could do is prevent results coming up for this GitHub dork. If the individuals who uploaded these cookie databases were made aware of what they'd done, they'd s*** their pants."
Marlin acknowledges that affected GitHub users deserve some blame for failing to prevent their cookies.sqlite databases from being included when they committed code and pushed it to their public repositories. "But there are nearly 4.5k hits for this dork, so I think GitHub has a duty of care as well," he said, adding that he's alerted the UK Information Commissioner's Office because personal information is at stake.
[6]
Marlin speculates that the oversight is a consequence of committing code from one's Linux home directory. "I imagine in most of the cases, the individuals aren't aware that they've uploaded their cookie databases," he explained. "A common reason users do this is for a common environment across multiple machines."
An old issue, still unfixed
GitHub dorks are not new, but they often only affect a single service, like AWS, Marlin said. This particular gaffe is troubling because it could allow an attacker to access any internet-facing website to which the GitHub user was authenticated at the time the cookie files were committed. He added that dorks for other browsers can probably also be found.
Exploitation, Marlin said, would be very easy. It's just a matter of creating a new Firefox profile on your local machine and then downloading the cookies.sqlite file and placing it within the Firefox profile folder. "You'll be authenticated on any services which the user was logged in on when they committed the database," explained Marlin.
There's a theoretical complication. Firefox offers an option to [7]protect logins and passwords . But as far as we can tell, that doesn't apply to the cookies.sqlite file. The Register was able to examine multiple Firefox cookie databases with Marlin's guidance.
[8]GitHub bug briefly gave valid authenticated session cookies to wrong users
[9]Be careful where you log into GitHub: Dev visits Iran, opens laptop, gets startup's entire account shut down
[10]YouTubers fell for shady 'sponsors' who seized, then sold, accounts
[11]My life as a criminal cookie clearer: Register vulture writes Chrome extension, realizes it probably breaks US law
When the visibility of cookies came up five years ago as a Firefox macOS bug submission, it was [12]closed .
And even if the cookies.sqlite file were protected by a database-specific password, it probably wouldn't offer much protection: Various [13]open source projects [14]offer the ability to crack .sqlite files, and there are commercial offerings of this sort too.
To underscore the seriousness of exposing these databases, consider this recently described [15]Android PoC exploit of CVE-2020–15647, used to exfiltrate the Firefox cookies database.
[16]
Mozilla confirmed Marlin's claims about the risk of exposing these files in an email to The Register on Thursday.
"Protecting the privacy of internet users is at the core of Mozilla’s work," a Mozilla spokesperson said. "When using code hosting services, we encourage users to use caution when considering the sharing of private data directly on public websites. When choosing to backup sensitive Firefox profile data, Mozilla recommends Firefox Sync, which encrypts and safely stores files within Firefox servers."
One mitigating factor at least is that sessions and associated cookies tend to expire relatively quickly.
There's precedent for GitHub to take action to help those who have been unwittingly publishing their cookie databases. The social code biz has been scanning for exposed credentials in repos [17]since 2015 and now scans for more than 70 different types of secrets. Here's one more to add to the list.
GitHub did not respond to a request for comment. ®
Get our [18]Tech Resources
[1] http://kb.mozillazine.org/Cookies.sqlite
[2] http://kb.mozillazine.org/Profile_folder_-_Firefox
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZbbHw52dhVSUI33lT29@QAAAQ0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZbbHw52dhVSUI33lT29@QAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZbbHw52dhVSUI33lT29@QAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZbbHw52dhVSUI33lT29@QAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://support.mozilla.org/en-US/kb/use-primary-password-protect-stored-logins
[8] https://www.theregister.com/2021/03/09/github_authentication_bug/
[9] https://www.theregister.com/2021/01/05/github_iran_block/
[10] https://www.theregister.com/2021/10/22/russian_crims_lured_youtubers_with/
[11] https://www.theregister.com/2020/07/21/cookie_clearing_chrome_extension_dmca/
[12] https://bugzilla.mozilla.org/show_bug.cgi?id=1331238
[13] https://github.com/unode/firefox_decrypt
[14] https://github.com/lclevy/firepwd
[15] https://infosecwriteups.com/firefox-and-how-a-website-could-steal-all-of-your-cookies-581fe4648e8d
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZbbHw52dhVSUI33lT29@QAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://github.blog/2021-06-08-securing-open-source-supply-chain-scanning-package-registry-credentials/
[18] https://whitepapers.theregister.com/
Re: How does anyone manage to do this?
In which case could a .ssh folder not be committed too?
Re: How does anyone manage to do this?
I indeed wrote a program that functions like dropbox and uses GitHub (and mirrors to GitLab and BitBucket) as a backend (It even splits files to <100MB chunks and recombines them behind the scenes ;).
But, only a weirdo would share the root of their $HOME directory... The sharing is usually constrained to a folder (i.e ~/DropBox).
I don't think they will ever be able to make a public service idiot proof for *these kinds* of users.
If the individuals who uploaded these cookie databases were made aware of what they'd done, they'd s*** their pants."
They should not shit their pants. The shit needs to be expelled at record speed. They should actually be banned from using the public interwebs. The users doing a commit of their home folder with private stuff to a public site is just too stupid. They deserve to shit themselves and all shit should hit a fan blowing in their faces, at record speed.
Github, as a public accessible site, is a bad match for private stuff. period. Learn the tools and consequences before you shit yourself in public, idiots.
Thank god I only use my github login for comments on other devs projects.
I keep all my projects on GitLab instead. Mind you, now they have been sold off to venture capitalists, maybe security will erode there too.
I guess the moral is: never trust anyone else's security, and never trust yourself that much either.
Re: Thank god I only use my github login for comments on other devs projects.
This has nothing really to do with GitLab vs GitHub or anything like that. Anyone stupid enough to put their cookie files on GitHub can be stupid enough to put them on GitLab.
These are the same morons that make their AWS buckets public and store cleartext passwords and write firmware update systems that don't require authentication.
Should all software include a gitignore file?
Just asking. You can't fix "stupid"
How does anyone manage to do this?
How does someone manage to commit a FF profiles folder?
You normally create a repo for each project directory.
Are people creating a repo for their entire home directory - so if they forget to exclude something it gets added? Perhaps to use github as free backup?