HomeSecurityAre you using PAC files? Beware of the NPM package error

Are you using PAC files? Beware of NPM package error

Recently, independent software developer Tim Perry, creator of the HTTP Toolkit for intercepting and debugging web traffic, decided to add proxy support to his product, which like a lot of software these days, is written using Node.js.

PAC

Node.js is the project that took JavaScript out of your browser and turned it into a complete application development system, something like Java.

See also: Google Chrome V8 JavaScript engine vulnerability: Update immediately

Along with the JavaScript core that uses the V8 JavaScript from Chromium , Node.js software usually also relies on NPM, the Node package manager, and the NPM registry, a truly massive repository of open source tools and programming.

The NPM registry covers everything from basic text formatting to full facial recognition and almost everything in between.

Instead of writing all of the code in your project yourself, or even most of it, you simply list the additional packages you want to use and NPM will pick them up for you, along with any additional packages that the package you've selected needs and all other packages that need those packages, until finally every piece of additional code needed to complete the project is automatically detected and installed.

As you can imagine, this can become a potential security nightmare. Adding a single package to your project can require a bunch of additional packages, each of which may have been written by a different person you don't know.

This method is known as a dependency tree and can be particularly dangerous. Perry himself discovered this danger recently when he decided to use a popular NPM package called Proxy-Agent to provide the proxy support he wanted in his HTTP Toolkit product.

Perry installed and started using Proxy-Agent and its entire dependency tree without reviewing the newly acquired components in his project. As a result, he encountered a security flaw, codenamed CVE-2021-23406, in a proxy dependency called Pac-Resolver, which is a secondary component that helps your code deal with the PAC, or proxy auto-configuration, process.

See also: New toolkit creates custom phishing pages in real time

Are you using PAC files? Beware of NPM package error

PAC files are not just lists of IP numbers or server names for data about where your network's official proxy servers are located. They are intended to be ingested and used in your browser, and as such were intentionally designed to be more flexible than a simple list of static data.

Indeed, a PAC file consists of JavaScript that can dynamically determine whether a proxy server is needed and if so where to find it on the network. As Perry notes, the PAC file format dates back a quarter of a century and first appeared as a "feature" in the Netscape.

Of course, Perry didn't plan to run PAC files in a browser, but as part of the HTTP Toolkit software, which runs as a regular application, potentially giving JavaScript a much greater reach and power in this scenario.

Therefore, he decided to take a look at how the developers of the proxy configuration code he had chosen had addressed the security implications of retrieving and executing external JavaScript.

He discovered that the code used a node component called vm, short for virtual machine, which allows you to set up a new JavaScript instance, or state, where you won't interfere with code running on other node instances in your application.

This is a handy precaution if you want two parts of your code to do separate things in such a way that they can't accidentally step on each other.

Perry realized that the original developer was using the vm library for both programming safety and security in general, apparently assuming that a new vm instance was not only separate from other vm instances in the application, but also strictly sandboxed in its own little isolated JavaScript world.

Perry quickly worked out how to use a normal JavaScript programming technique to execute code inside the new vm instance that had full access to the external data of the main Node.js application.

Technically, this is an RCE bug in the proxy configuration process, where RCE is used for remote code execution.

See also: WooCommerce fixes a serious vulnerability

NPM security gap

RCE means that untrusted content coming from an untrusted source can intentionally do something sneaky that is not supposed to be allowed, without any warnings appearing.

Exploiting this flaw typically allows the official proxy PAC file of a private network to be changed to include trapped JavaScript.

What can we do?;

If you have Node.js software that uses Pac-Resolve, Pac-Proxy-Agent , or Proxy-Agent, make sure you have version 5.0.0 or later for these packages.

Regularly review the Node.js modules your products are based on. You should consider the additional time and expertise in the software release process.

Consider the security restrictions of the libraries you use.

Don't assume that widely used packages are secure. Bugs like CVE-2021-23406 are likely to go undiscovered for a long time if someone doesn't look for them.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS