Scriptless attacks: Stealing more pie without touching the sill

Scriptless attacks: Stealing more pie without touching the sill
复制标题

无脚本攻击:不碰门槛就偷更多馅饼

DOI:
10.3233/jcs-130494
复制
发表时间:
2014
期刊:
J. Comput. Secur.
影响因子:
--
通讯作者:
Jörg Schwenk
Jörg Schwenk
中科院分区:
--
文献类型:
--
作者:
M. Heiderich;Marcus Niemietz;Felix Schuster;Thorsten Holz;Jörg Schwenk

文献摘要

被引文献

相似文献

跨站脚本(XSS)攻击由于其高度的实际影响,已经引起了全球安全社区成员的广泛关注。以同样的方式,已经提出了过多的或多或少有效的防御技术,解决XSS漏洞的原因和影响。因此,攻击者通常无法再注入甚至无法在几个现实场景中执行任意脚本代码。在本文中,我们研究了在XSS和类似脚本攻击之后仍然存在的攻击面,这些攻击被认为是通过阻止攻击者执行JavaScript代码来减轻的。我们解决的问题是,攻击者是否真的需要执行JavaScript或类似的功能,以执行攻击,旨在窃取信息。令人惊讶的结果是,攻击者可以将层叠样式表(CSS)与其他Web技术(如纯HTML、非活动SVG图像或字体文件)结合使用。采用了几个案例研究,我们讨论了所谓的无脚本攻击,并证明对手可能不需要执行代码,以保持他的能力,从保护良好的网站提取敏感信息。更确切地说,我们表明攻击者可以使用看似良性的功能来构建侧信道攻击,这些攻击可以测量和泄露给定网页上显示的几乎任意数据。最后,我们将讨论针对此类攻击的潜在缓解技术。此外,我们还实现了一个浏览器补丁,使网站能够在分离视图或弹出窗口中进行加载。这种方法被证明对于防止我们在这里讨论的某些类型的攻击是有用的。
Due to their high practical impact, Cross-Site Scripting (XSS) attacks have attracted a lot of attention from the members of security community worldwide. In the same way, a plethora of more or less effective defense techniques have been proposed, addressing both causes and effects of XSS vulnerabilities. As a result, an adversary often can no longer inject or even execute arbitrary scripting code in several real-life scenarios. In this article, we examine an attack surface that remains after XSS and similar scripting attacks are supposedly mitigated by preventing an attacker from executing JavaScript code. We address the question of whether an attacker really needs to execute JavaScript or similar functionality to perform attacks aiming for information theft. The surprising result is that an attacker can abuse Cascading Style Sheets (CSS) in combination with other Web techniques like plain HTML, inactive SVG images, or font files. Having employed several case studies, we discuss so called scriptless attacks and demonstrate that an adversary might not need to execute code to preserve his ability to extract sensitive information from well-protected websites. More precisely, we show that an attacker can use seemingly benign features to build side-channel attacks that measure and exfiltrate almost arbitrary data displayed on a given webpage. We conclude this article with a discussion of potential mitigation techniques against this class of attacks. In addition, we have implemented a browser patch that enables a website to make a vital determination as to being loaded in a detached view or a pop-up window. This approach proves useful for prevention of certain types of attacks we here discuss.