A Zero-Day Faw in the TOR Browser Revealed on Twitter

in #writing6 years ago

The flows dealer Zerodium revealed a breach, which is a feat for Tor Browser. And the company would still have many more flaws in stock for this browser...

nkjnk.jpg
Source

The Zerodium company, whose speciality is the purchase and the resale of zero-day flaws, has delivered one of its goods for free. It has revealed on Twitter the existence of a zero-day flaw in Tor Browser version 7, allowing to by-pass the NoScript extension protection of the browser.

This one prevents the execution of active codes on the visited Web pages, such as Javascript, Java, Flash or Silverlight, so improving the protection against the cross- attacks scripting attacks or the fingerprinting.

Capture d’écran (3).png
Source

As can be seen, the flaw is very simple: it is enough that the header of the web page defines the type of content (Content-Type) as "text / html; json". From there, the NoScript feature will allow to pass all the Javascript codes.

"This Tor/NoScript bug is so simple that it looks like a backdoor. It deserves PwnieAwards 2019! Congratulations to the researcher who discovered it and who sold it to Zerodium", underlines Chaouki Bekrar, the CEO of Zerodium on Twitter.

Since then, the flaw was patched by the NoScript developers. Users are therefore invited to download and to install the version 5.1.8.7 of this extension. But the simplest would still to upgrade to the version 8 of Tor Browser. This one is not concerned by this vulnerability because it embeds a more recent version of NoScript (10.1.9.1).

Questioned by ZDnet, Chaouki Bekrar explains that this flow comes from a bug bounty organized in December, 2017, during which the company would have received and bought numerous exploits Tor ".

According to the Zerodium business model, this vulnerability has been shared with the company’s "governmental customers". "We decided to reveal this exploit since it reached its end of life and it does not affect the version 8 of Tor Browser", specifies the leader. We hesitate to thank him anyway.

Anonymity is SO important and TOR is not the only way to protect it, my next article will show you why/how you should do it! STAY LOG steemians ;-)

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Sort:  

Tor browser and tor network is questionable from ground to top. Never trust that tunneling and never make your system depend on it ONLY, can be the brief advice to the all common users.

Wow excellent information sharing thanks for sharing @vijbzabyss, I will keep your guides . Upvoted and followed

I appreciate a lot! Thank you for your time! :)

Wow. This is huge. Not good to have a backdoor in Tor.

Posted using Partiko Android

The worst's coming..

This is great info for users of the tor network we appreciate your efforts

Thanks to you eric!

hmm..that's so bad

As you say, but that flaw doesn't exist anymore ;-)

Coin Marketplace

STEEM 0.19
TRX 0.15
JST 0.029
BTC 63501.83
ETH 2650.23
USDT 1.00
SBD 2.81