HomeSecurityTwo vulnerabilities affect LastPass | They fully expose the password

Two vulnerabilities affect LastPass | Fully expose code

July 27, 2016, will not go down in history as a quiet day for the LastPass team, as two vulnerabilities that surfaced online could allow an attacker to compromise their application.

The first is an issue discovered by Mathias Karlsson of Detectify. The researcher explains in a blog post that the problem was in the JavaScript code that parsed the URL of the LastPass page, working from above.

Two vulnerabilities affect LastPass | Fully expose code

He discovered that by tricking a user into entering a URL in the form attacker-site.com/@twitter.com/@script.php, the LastPass URL parsing function would trick them into thinking they were on twitter.com, instead of attacker-site.com .

Because LastPass comes with an autofill feature, that application would have pre-filled any login form on that page with the user's credentials.

If the attacker ran JavaScript code on this site that would automatically parse and record any text entered into login forms, they would be able to obtain the user's credentials.

The good news is that Karlsson informed LastPass about the issue a while ago and the development team fixed the problem the same day, releasing an updated version of their app.

However, Karlsson wasn't the only one who hacked LastPass. Google Project Zero lead researcher Tavis Ormandy also discovered an issue that could lead to the full exposure of LastPass.

The bad news is that this issue is not patched in current LastPass versions. The good news is that no one outside of Ormandy and the LastPass team knows what this problem is, making it extremely unlikely for anyone to exploit it.

This would normally be called a zero-day vulnerability, but that is not the case, since no one can take advantage of it before it is patched.

The LasPass team has also fixed the second flaw. The team describes the problem on blog as follows:

“The second report was made yesterday by Google Security Team researcher Tavis Ormandy, who contacted our team to report a message-hijacking bug affecting the LastPass Firefox addon. First, an attacker would have to successfully lure a LastPass user into accessing a malicious website. Once inside, Ormandy demonstrated that the website could then perform LastPass actions in the background without the user’s consent, such as deleting data. This issue has been fully addressed and an update with a fix has been sent to all Firefox using LastPass 4.0.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS