Cross Context Scripting with Sage

This month we have a guest blogger and his name is David Kierznowski, the founder of Operation n - the adventures of Michaels Daw. David and I have been working together on various security related projects. He currently works as a security analyst and researcher. David contacted me after he found interesting anomaly with Sage Firefox Extension. These are his words:

I would often keep abreast of new vulnerabilities and exploits via my RSS feeds. Visiting page after page was just never fun. RSS allowed me to categorise, organise and track the security mayhem on the Internet. What was the point of employing a security analyst who was outdated and outgunned?

I decided to play with Sage, which is a popular RSS extension for Mozilla Firefox. It had a friendly interface and a nice option to turn HTML tags on and off. This was a feature I was certainly interested in. It meant I could prevent a number of attacks outlined by SPI Dynamic's recent RSS Injection whitepaper. The recommendation given in this paper was the typical recommendation given to XSS attacks. Escape <> to &lt;&gt;.

I turned off HTML tags and continued on as normal. However, something odd happened. When rendering my whitepaper Awakening the Sleeping Giant an insert of JavaScript was executed in my browser. How bazaar I thought. The security enabled feature makes me vulnerable. Sage was vulnerable to XSS! I immediately contacted pdp. We worked on it for 30 minutes and for those 30 minutes all you could hear were sinister laughs.

The proof of concept feed can be downloaded from the following URL.