Lastpass firefox not working. Critical bugs identified in LastPass password manager, Chrome and Firefox extensions

Lastpass firefox not working. Critical bugs identified in LastPass password manager, Chrome and Firefox extensions

17.09.2020

Back in the summer of 2016, Google Project Zero specialist Tavis Ormandy is sincere: "Do people really use this LastPass thing?" Then Ormandy discovered a vulnerability in the code of the LastPass add-on for Firefox 0-day, which allowed him to remotely compromise all user passwords.

Now, almost a year later, the expert has decided to put the security of LastPass to the test, and, unfortunately, the application cannot be said to have passed this test. Ormandy writes that he found an issue in the official LastPass extension for chrome browser... According to the researcher, the content_scrip extension contains a vulnerability, an attack on which could lead to the compromise of all credentials stored in the application. Moreover, to implement an attack, an attacker only needs to lure the user to a malicious site.

The researcher explains that the script is only used to access a specific domain on lastpass.com, and if you take a closer look at how it works, it looks like this:

Here, as Ormandy notes, lies the mistake. The script proxies unauthenticated window messages to the extension, which can be dangerous, because anyone can do the following:

This will give the attacker full access and force LastPass to execute RPC commands, of which there can be hundreds, but the most dangerous, of course, is the ability to copy and populate passwords. In some cases, this can even lead to the execution of arbitrary code on the user's machine, through the operation of openattach. As an example, Ormandy demonstrates launching a regular calculator (calc.exe).

The LasPass developers, apparently, have already fixed the problem in the Chrome extension by disabling 1min-ui-prod.service.lastpass.com. However, some users note that the server is still running for them, and the vulnerability is still relevant. LastPass for Chrome users should probably disable the extension for now and wait for the full fix, as version 4.1.42, dated March 14, 2017, was still vulnerable.

It's worth noting that Tavis Ormandy found another very similar bug in the LastPass Firefox addon last week. The vulnerability in the same way allows you to extract all user passwords if he visits a malicious site.

This problem has not been fixed yet. The LastPass developers have already prepared a patch, but the revised version 3.3.2 is still under review by Mozilla specialists. Also, the authors of LastPass emphasized that the 3.x branch is still considered outdated, and users are encouraged to move to the safer 4.x branch.

But LastPass's problems don't even end there. Today, March 22, 2017, Tavis Ormandy warned that the LastPass Firefox addon contains another bug that allows you to steal other people's passwords for any domain. Moreover, this time the more modern and secure version 4.1.35 is vulnerable. The expert promises to publish the details in the near future.

© 2020 hecc.ru - News of computer technologies