• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Browsers with extensions? How they steal the data

Browsers with extensions? How they steal the data

19/01/2019 21:55 by giorgos

Malicious websites can take advantage of the browsers' extensions APIs to run code within the browser and steal sensitive information such as bookmarks, browsing history, or even user cookies.

Of course an attacker can with cookies can capture the user's active sessions and access sensitive accounts such as email inboxes, social profiles, or bank accounts, etc.browsers - Browsers with extensions? How they steal data

In addition, the same APIs (always talking about extensions used by browsers) can be used to enable malicious files to be downloaded and stored on the user's device. This data is stored in the storage of an extension, and can later be used to track users across the web.

These types of attacks are no longer theoretical, having recently been proven in a study published by Dolière Francis Somé, a researcher at the Université Côte d'Azur and INRIA, the French research institute.

Somé developed a tool and looked over 78.000 extensions for Chrome, Firefox and Opera. He managed to identify 197 extensions that allowed the API's internal communication interface to appear with web applications. This can give malicious websites access to the data stored in a user's browser, data that should normally not be accessible.

ChromeFirefoxOperaTotal
Extensions analyzed66,4019,3912,52378,315
Suspicious extensions3,3034832103,996
Execute code152219
Bypass SOP489663
Read cookies8--8
Read browsing history40--1
Read bookmarks371-38
Get extensions installed33--33
Store / retrieve data852390
Trigger downloads295236
Total of unique extensions1711610197

The French researcher reports that he was surprised by the results, as only 15 (7,61%) of 197 extensions were development tools, a category of extensions that usually have full control over what happens to a browser and are from applications that do not must have security holes.

About 55% of all extensions had less than 1.000 installations, but over 15% had over 10.000.

Somé said he advised browser developers of his findings before publishing the survey to the public in early January.

"Everyone recognized the problems," Somé says. “Firefox has removed all the extensions I mentioned. Opera has also removed all extensions but there are 2 more that can be exploited to enable downloads. "

“Chrome also recognized the problem. We are still discussing together the possible measures to be taken. ”

The researcher also created a tool that allows users to check if their extensions contain a susceptible API that can exploit malicious websites. The tool is web-based and hosted on this page.

To use it, you'll need to copy-paste the contents of the manifest.json file of the extension you are interested in.

Watch the videos published by the researcher

If you want to read more in Somé's work: EmPoWeb: Empowering Web Applications with Browser Extensions, ”You can download it as a PDF from here and here.

_______________________

  • PDF 5 free online processing services
  • Hacking the most commonly used tools
  • VLC download videos online & convert them as you wish
Browsers with extensions? How they steal the data was last modified: 19 January, 2019, 9: 59 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: queues, cookies, Downloads, extensions, I'm sure

You May Also Like

Chrome 88 share pages with QR Code
Do you have anything to post? Send it to Your Post
The best free QR code creation software

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Windows 10 Mobile Support Fee
Next Post: Mozilla integrates an adblocker in Firefox Focus 9.0 »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.