SafeBrowsing bypass by web socket
Categories
(Toolkit :: Safe Browsing, defect, P3)
Tracking
()
People
(Reporter: avkovaleff, Assigned: dimi)
References
(Blocks 1 open bug)
Details
(Keywords: csectype-other, reporter-external, sec-low, Whiteboard: [reporter-external] [client-bounty-form] [verif?][adv-main68+] tp-leak)
Attachments
(3 files)
Comment 2•7 years ago
|
||
Updated•7 years ago
|
Comment 5•7 years ago
|
||
Updated•7 years ago
|
Updated•7 years ago
|
Updated•6 years ago
|
| Assignee | ||
Comment 11•6 years ago
|
||
(In reply to Johann Hofmann [:johannh] from comment #10)
Dimi, do you know about the state of this? :)
Yes, This will be fixed after landing patch in Bug 1522412, which should be done within this week :)
| Assignee | ||
Comment 12•6 years ago
|
||
Bug 1522412 has landed so this issue should be fixed.
I'll add a testcase to verify this.
| Assignee | ||
Updated•6 years ago
|
| Assignee | ||
Comment 13•6 years ago
|
||
I have verified that websocket is blocked by SafeBrowsing via:
- Add "echo.websocket.org" to safe browsing malware database
- Go to https://www.websocket.org/echo.html, make sure we can't connect to echo.websocket.org
- remove the malware test table from preference
- connect to echo.websocket.org again, can establish the connection now.
So this issue is fixed by Bug 1522412
Updated•6 years ago
|
Updated•6 years ago
|
Comment 14•6 years ago
|
||
(In reply to Dimi Lee [:dimi][:dlee] from comment #13)
- Add "echo.websocket.org" to safe browsing malware database
Could you please detail here? How exactly can I add "echo.websocket.org" to safe browsing malware database?
| Reporter | ||
Comment 15•6 years ago
|
||
(In reply to Andrey from comment #9)
Hello!
Any update here? Probably bounty and / or CVE? =)
Hi! Still actual question =)
Comment 16•6 years ago
|
||
Unfortunately this bug does not qualify for a security bug bounty.
| Assignee | ||
Comment 17•6 years ago
|
||
(In reply to Brindusa Tot[:brindusat] from comment #14)
(In reply to Dimi Lee [:dimi][:dlee] from comment #13)
- Add "echo.websocket.org" to safe browsing malware database
Could you please detail here? How exactly can I add "echo.websocket.org" to safe browsing malware database?
Hi Brindusa,
Safe browsing doesn't have a public API to do that, I did that by manually modifying the test entries in our codebase[1].
We have a preference to add a domain to tracking protection for testing, we can do the same thing for safe browsing.
Would that help?
Comment 18•6 years ago
|
||
I think having a manual way to add safe browsing blocking would help for verifying this bug, however, I'm not sure if the effort is worthwhile if you think there wouldn't be a general and future use for it.
| Assignee | ||
Comment 19•6 years ago
|
||
(In reply to Brindusa Tot[:brindusat] from comment #18)
I think having a manual way to add safe browsing blocking would help for verifying this bug, however, I'm not sure if the effort is worthwhile if you think there wouldn't be a general and future use for it.
I think that will be useful, I filed bug 1546586 to implement this.
Updated•6 years ago
|
Updated•6 years ago
|
Updated•5 years ago
|
Updated•5 years ago
|
Updated•1 year ago
|
Description
•