SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Exploit Vendor Drops Tor Browser Zero-Day on Twitter
Date    Tuesday September 11 2018, @12:18PM
Author    Fnord666
Topic   
from the land-of-tor dept.
https://soylentnews.org/article.pl?sid=18/09/11/046259

An Anonymous Coward writes:

A company that sells exploits to government agencies drops Tor Browser zero-day on Twitter after recent Tor Browser update renders exploit less valuable.

Zerodium, a company that buys and sells vulnerabilities in popular software, has published details today on Twitter about a zero-day vulnerability in the Tor Browser, a Firefox-based browser used by privacy-conscious users for navigating the web through the anonymity provided by the Tor network.

In a tweet, Zerodium said the vulnerability is a full bypass of the "Safest" security level of the NoScript extension that's included by default with all Tor Browser distributions.

NoScript is a browser extension that uses a whitelist approach to let the user decide from what domains the browser can execute JavaScript, Flash, Java, or Silverlight content. It is included with all Tor Browser distributions because it provides an extra layer of security for Tor Browser users.

Zerodium's Tor zero-day basically allows malicious code to run inside the Tor Browser by bypassing NoScript's script-blocking ability.


Original Submission

Links

  1. "drops Tor Browser zero-day" - https://www.zdnet.com/article/exploit-vendor-drops-tor-browser-zero-day-on-twitter/
  2. "In a tweet" - https://twitter.com/Zerodium/status/1039127214602641409?s=19
  3. "NoScript" - https://noscript.net/
  4. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=28932

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Exploit Vendor Drops Tor Browser Zero-Day on Twitter on 2024-04-27 07:04:59