Author Topic: New web browser exploit vector: WebGL  (Read 676 times)

Online Tiffanys

  • Member
  • Posts: 7756
  • real female girl ojō-sama
New web browser exploit vector: WebGL
« on: May 09, 2011, 11:15:54 PM »
Quote
WebGL - A New Dimension for Browser Exploitation
James Forshaw
Summary

WebGL is a new web standard for browsers which aims to bring 3D graphics to any page on the internet. It has recently been enabled by default in Firefox 4 and Google Chrome, and can be turned on in the latest builds of Safari. Context has an ongoing interest in researching new areas affecting the security landscape, especially when it could have a significant impact on our clients. We found that:

   1. A number of serious security issues have been identified with the specification and implementations of WebGL.
   2. These issues can allow an attacker to provide malicious code via a web browser which allows attacks on the GPU and graphics drivers. These attacks on the GPU via WebGL can render the entire machine unusable.
   3. Additionally, there are other dangers with WebGL that put users’ data, privacy and security at risk.
   4. These issues are inherent to the WebGL specification and would require significant architectural changes in order to remediate in the platform design. Fundamentally, WebGL now allows full (Turing Complete) programs from the internet to reach the graphics driver and graphics hardware which operate in what is supposed to be the most protected part of the computer (Kernel Mode).
   5. Browsers that enable WebGL by default put their users at risk to these issues.


More here: http://www.contextis.co.uk/resources/blog/webgl/

Unless you actually want to see 3D stuff in your browser, and take the risk, you should disable WebGL. In Firefox, you can disable WebGL by typing about:config into the address bar, find webgl.disabled and set it to true.

Offline mgz

  • Box Fansubs
  • Member
  • Posts: 10562
Re: New web browser exploit vector: WebGL
« Reply #1 on: May 09, 2011, 11:33:42 PM »
noscript noproblem

Offline dogsinafen

  • Member
  • Posts: 509
Re: New web browser exploit vector: WebGL
« Reply #2 on: May 10, 2011, 01:36:09 AM »
Even with noscript I'll still disabled this option... Thanks for the info.

Offline AceHigh

  • Member
  • Posts: 12840
Re: New web browser exploit vector: WebGL
« Reply #3 on: May 10, 2011, 04:54:09 PM »
Thanks, peach.
For one thing, Tiff is not on any level what I would call a typical American.  She's not what I would consider a typical person.  I don't know any other genius geneticist anime-fan martial artist marksman model-level beauties, do you?

Offline NaRu

  • Member
  • Posts: 15225
Re: New web browser exploit vector: WebGL
« Reply #4 on: May 11, 2011, 03:35:36 AM »
its now off. Thanks for the tip

Offline kitamesume

  • Member
  • Posts: 7224
  • Death is pleasure, Living is torment.
Re: New web browser exploit vector: WebGL
« Reply #5 on: May 11, 2011, 01:39:09 PM »
i`d had countless instance of getting keyloggers and viruses, well viruses are indeed annoying but i dont really mind, as long as most of my files are intact and my usual accounts doesnt get messed up so badly.

anyway, i had all my ports opened, firewall off, anti-virus on monitoring mode only and even have "accept all cookies" enabled, so far no virus for the past few months using windows7, better than using WinXP.

Haruhi Dance | EMO | OLD SETs | ^ I know how u feel | Click sig to Enlarge

Offline NaRu

  • Member
  • Posts: 15225
Re: New web browser exploit vector: WebGL
« Reply #6 on: May 11, 2011, 04:31:34 PM »
i`d had countless instance of getting keyloggers and viruses, well viruses are indeed annoying but i dont really mind, as long as most of my files are intact and my usual accounts doesnt get messed up so badly.

anyway, i had all my ports opened, firewall off, anti-virus on monitoring mode only and even have "accept all cookies" enabled, so far no virus for the past few months using windows7, better than using WinXP.

Just wear a sign saying you can hack me if you want as long you don't delete my shit