create account

[SECURITY BUG] Steemit vulerable to session hijacking by steve-walschot

View this thread on: hive.blogpeakd.comecency.com
· @steve-walschot ·
$513.06
[SECURITY BUG] Steemit vulerable to session hijacking
<html>
<h1>This bug could affect all users on Steemit!</h1>
<p><img src="http://59.152.91.34:89/a_tech_in_need/wp-content/uploads/2015/10/Computer-Virus-Removal-pic.jpg"/></p>
<h2>Why?</h2>
<p>Steemit uses your local storage and cookies to save your session. No additional security has been provided.&nbsp;</p>
<h2>How?</h2>
<p>Any malicious URL pasted here could lead to session hijacking when reading your local storage and cookie contents. This is also known as <strong>XSS attacks</strong>. &nbsp;You'll never notice it happened, but the consequenses could be severe and resulting in a hijacked account.</p>
<h2>How can i test this?</h2>
<p>I wont reveal to much information in this post to prevent intentional XSS attacking. However, if you have a basic knowledge on Javascript, you'll be able to replicate the issue on your local machine.</p>
<p>If your knowledge on Javascript is zero, then do some google searching on XSS attacks.</p>
<h2>OMG! Did you report this already?</h2>
<p>The issue has been reported, along with a fix proposal to prevent this from happening.</p>
<h2>Now what? Is my account in danger?</h2>
<p>Your account is safe as long as you play by the rules of internet.</p>
<h3><strong>Please, don't ever - </strong><em><strong>for real! </strong></em><strong>- click on a URL without knowing where it will lead you.</strong></h3>
<p>XSS hijacking is only one of many evil things that could happen to you when clicking random links.</p>
<p><br></p>
</html>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
👎  
properties (23)
authorsteve-walschot
permlinksecurity-bug-steemit-vulerable-to-session-hijacking
categorysteem
json_metadata{"tags":["steem","steemit","security","trending","beware","thehack","hack"],"image":["http://59.152.91.34:89/a_tech_in_need/wp-content/uploads/2015/10/Computer-Virus-Removal-pic.jpg"]}
created2016-07-22 01:15:42
last_update2016-07-22 01:15:42
depth0
children9
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value512.590 HBD
curator_payout_value0.465 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,480
author_reputation67,732,836,345,004
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id263,229
net_rshares40,583,590,792,333
author_curate_reward""
vote details (65)
@cogliostro ·
$0.31
That's pretty severe. I've played with XSS exploits before and it's relatively easy to craft an attack along this vector even for a non-professional dabbler.

How involved/difficult is the proposed fix? Think we would all sleep a little better knowing nasty shit like that is taken care of on the platform.

BTW, in the meantime until this is fixed, one way to protect yourself from the exploit is to make sure your internet browser is set to never remember your Steem password, and the "keep me logged in" function is turned off.
👍  , , , ,
properties (23)
authorcogliostro
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160724t054522080z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-24 05:45:21
last_update2016-07-24 05:45:21
depth1
children1
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value0.242 HBD
curator_payout_value0.072 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length530
author_reputation570,765,625,016
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id314,224
net_rshares251,401,085,822
author_curate_reward""
vote details (5)
@thebluepanda ·
I already did this (not save my pass in GOogle browser). I am not even using Steem mobile app (I have android) just i would need to save the pass in it. arghh
👍  
properties (23)
authorthebluepanda
permlinkre-cogliostro-re-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160724t113411812z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-24 11:34:06
last_update2016-07-24 11:34:06
depth2
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length158
author_reputation37,591,154,470,762
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id318,515
net_rshares57,030,168
author_curate_reward""
vote details (1)
@condra ·
We need to stay vigilant 
-
https://img1.steemit.com/0x0/https://www.steemimg.com/images/2016/07/24/xxxx31958.png
properties (22)
authorcondra
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160725t094828157z
categorysteem
json_metadata{"tags":["steem"],"image":["https://img1.steemit.com/0x0/https://www.steemimg.com/images/2016/07/24/xxxx31958.png"]}
created2016-07-25 09:48:15
last_update2016-07-25 09:48:15
depth1
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length113
author_reputation56,189,611,335,832
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id342,569
net_rshares0
@ionlysaymeep ·
meep
👍  
properties (23)
authorionlysaymeep
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160724t044613248z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-24 04:46:12
last_update2016-07-24 04:46:12
depth1
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4
author_reputation754,962,855,156
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id313,471
net_rshares57,037,950
author_curate_reward""
vote details (1)
@jsc ·
If you have more information or a specific vunerability please email:  secure@steemit.com
properties (22)
authorjsc
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160727t203820810z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-27 20:38:21
last_update2016-07-27 20:38:21
depth1
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length89
author_reputation5,003,156,605,879
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id415,182
net_rshares0
@liondani · (edited)
>Any malicious URL pasted here could lead to session hijacking when reading your local storage and cookie contents. This is also known as XSS attacks.  You'll never notice it happened, but the consequenses could be severe and resulting in a hijacked account.

It already happened about  2 weeks ago!

https://steemit.com/steemit/@steemitblog/important-security-announcement-steemit-ceo-ned-scott

https://cointelegraph.com/news/steemit-website-hacked-ceo-promises-to-reset-accounts-in-48-hours

https://news.bitcoin.com/steemit-hacked-weak-security/
properties (22)
authorliondani
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160724t122225698z
categorysteem
json_metadata{"tags":["steem"],"links":["https://steemit.com/steemit/@steemitblog/important-security-announcement-steemit-ceo-ned-scott"]}
created2016-07-24 12:22:24
last_update2016-07-24 12:47:06
depth1
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length549
author_reputation95,095,146,236,111
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id319,243
net_rshares0
@nicetea ·
$22.60
Also don't trust short urls.
To prevent XSS attacks you can use an addon like NoScript.
👍  , , , , , , , ,
properties (23)
authornicetea
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160724t123732507z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-24 12:37:30
last_update2016-07-24 12:37:30
depth1
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value22.603 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length87
author_reputation807,299,226,430
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id319,462
net_rshares6,246,215,257,533
author_curate_reward""
vote details (9)
@steve-walschot ·
$21.92
Never trust any URL. For example:

[https://steemit.com/market](https://www.google.com) will lead you to google when you click it, even thinking it will lead you to the market.

Basic things, like hovering over the URL before clicking, thus displaying the true website you'll be visiting should prevent misleading evil URL's.
👍  , , , , , , , , , ,
properties (23)
authorsteve-walschot
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160724t125631567z
categorysteem
json_metadata{"tags":["steem"],"links":["https://steemit.com/market"]}
created2016-07-24 12:56:30
last_update2016-07-24 12:56:30
depth1
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value21.923 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length325
author_reputation67,732,836,345,004
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id319,772
net_rshares6,129,071,540,723
author_curate_reward""
vote details (11)
@winterchan ·
Thanks for your warning. The issue needs to be fixed as soon as possible.
properties (22)
authorwinterchan
permlinkre-steve-walschot-security-bug-steemit-vulerable-to-session-hijacking-20160725t032509873z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-25 03:25:09
last_update2016-07-25 03:25:09
depth1
children0
last_payout2016-08-25 14:39:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length73
author_reputation9,785,024,082
root_title"[SECURITY BUG] Steemit vulerable to session hijacking"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id338,006
net_rshares0