Author Topic: LastPass security hole (cross site scripting) ... possibly solved now.  (Read 3663 times)

0 Members and 1 Guest are viewing this topic.

Hermite15

  • Guest
... thought it was worth starting a new thread

lastpass cross scripting vulnerability revealed:
http://www.theregister.co.uk/2011/03/01/password_management_site_xss_bug/
https://grepular.com/LastPass_Vulnerability_Exposes_Account_Details

forum thread:
http://forums.lastpass.com/viewtopic.php?f=12&t=60559

lastpass response:
http://blog.lastpass.com/2011/02/cross-site-scripting-vulnerability.html
http://blog.lastpass.com/2011/03/content-security-policy-csp-implemented.html

... I guess - if we don't take LP recent fixes into account - people using FF NoScript on any FF version or simply using FF4 (CSP implementation https://wiki.mozilla.org/Security/CSP/Specification ) are protected.

edit: to make things clear if needed, the issue obviously only exists or may exist when you login to your LastPass account directly on LastPass website, not when using the browser plugin.
« Last Edit: March 02, 2011, 04:56:39 PM by Logos »

Hermite15

  • Guest
just posted this on NS forums:
http://forums.informaction.com/viewtopic.php?f=8&t=5928#p25741

expecting feedback there...

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Thanks Logos. Please, post back the results. A lot of us use Lastpass... ::)
The best things in life are free.

Hermite15

  • Guest
what bothers me the most tbh is Chrome that doesn't have any serious JS and/or cross site scripting protection... there was something, experimental feature found in about:flags, called "XSS auditor", it's not there anymore in the last dev version. They may have fully integrated it but I don't see it in the change log, and there's no new option in the UI.

Hermite15

  • Guest

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
here's the answer from NoScript developer:
http://forums.informaction.com/viewtopic.php?f=8&t=5928&p=25805#p25803

Thanks Logos..!!
No wonder, that I like NS so much... ;)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Thanks Logos. NS is doing its job.
The best things in life are free.