HomeSecuritySame-Origin policy bypassed in Internet Explorer

Bypassing Same-Origin policy in Internet Explorer

The latest version of Internet Explorer does not properly separate elements from two different domains, allowing content belonging to one domain to appear in the context of the other.

SOP Bypass Internet Explorer

Web browsers have a protection measure called same-origin policy (SOP), a set of rules that ensure that the origin of a piece of information (a document or a script) is preserved and does not interact with a resource from another origin.

Security researcher David Leo identified a way to bypass the SOP in Internet Explorer and demonstrated the existence of the vulnerability by performing a cross-site scripting (XSS) on dailymail.co.uk.

Leo also released a proof-of-concept (PoC) that automates the attack, where arbitrary content is displayed within the DailyMail website. The address remains the same, but the content displayed is that selected by the researcher.

The PoC is recommended by opening a page on the researcher's website in Internet Explorer and following a link that triggers the vulnerability.

The Daily Mail website then loads in a separate frame, and seven seconds later the arbitrary content pops up, retaining the original Daily Mail address .

However, certain conditions are necessary for the attack to be successful, as Joey Fowler, a senior security engineer at Tumblr, points out. If the targeted website does not contain X-Frame-Options headers with “deny” or “same-origin” values, then the attack will be successful.

He also adds that this method bypasses the limitations of the HTTP-to-HTTPS and that, while the payload is injected, “most content security policies are also bypassed (with HTML injection instead of JavaScript).”

Leo tested on Internet Explorer 11 running on Windows 7, but the SOP also works in a Windows 8.1, with the latest version of the web browser.

An attack of this kind could be used by cybercriminals to steal sensitive information (credentials for online accounts) from the victim.

Using the same tactic, malicious files can be delivered without raising suspicions in the user that the download came from an untrusted source.

The discovery is particularly important, as multiple XSS attacks can be developed based on it .

Mozilla Firefox and Google Chrome are not affected by this bug.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS