Blaze Blog /

Security advisory: Porteus Kiosk security restrictions bypass

Security
Mar 29, 2017
2min read
Illustration of a pest killer cyborg burning down a bug with a flame thrower

Advisory information

Title: Porteus Kiosk security restrictions bypass
Advisory reference: BLAZE-01-2017
Product: Porteus Kiosk
Disclosure mode: Coordinated disclosure

Product description

Porteus Kiosk is a popular lightweight Linux designed to be used as a kiosk solution. It implements several restrictions with the intent to prevent malicious users from modifying the configuration of the Firefox browser and escaping the restricted browser environment to obtain access to the underlying operating system and filesystem.

Vulnerability details

In order to restrict access to the browser configuration facilities, Porteus Kiosk removed these menus from the browser interface. In addition, it implemented a blacklist filter to prevent the user from accessing protocols that can be abused to escape these restrictions, such as file:// and numerous chrome:// URIs.

During a security review of this kiosk solution it was found the blacklist was not enough to prevent the user from accessing configuration menus of the browser.

By typing any of these chrome URIs in Firefox, a user of the kiosk can access its configurations, password manager, etc.:

chrome://global/content/config.xul
chrome://browser/content/openLocation.xul
chrome://global/content/filepicker.xul
chrome://mozapps/content/plugins/pluginInstallerWizard.xul
chrome://passwordmgr/content/passwordManager.xul
chrome://browser/content/preferences/preferences.xul
chrome://browser/content/preferences/advanced.xul
chrome://browser/content/preferences/applications.xul
chrome://browser/content/preferences/connection.xul
chrome://browser/content/preferences/permissions.xul
chrome://browser/content/preferences/sanitize.xul
chrome://browser/content/preferences/security.xul
chrome://mozapps/content/downloads/downloads.xul
chrome://browser/content/safeMode.xul

For example, a malicious user can reconfigure the network preferences to point to an attacker-controlled proxy and launch other attacks from there, intercept traffic, and perform other malicious actions.

Fix and recommendations

The vulnerability has been addressed by Porteus Kiosk in release 4.0.0. It is recommended to upgrade Porteus Kiosk to its latest version.

Credits

This vulnerability was discovered and researched by Julio Cesar Fort from Blaze Information Security.

Disclosure timeline

May 24, 2016: Initial contact asking for the vendor's PGP key
May 24, 2016: Vendor responded, asking for details of the vulnerability to be sent via unencrypted e-mail
May 24, 2016: Vulnerability details sent unencrypted
May 24, 2016: Vendor informed the vulnerability has been fixed and a patch will be released in the next automatic update
May 28, 2016: A fix was released
March 28, 2017: Advisory released

References

Porteus Kiosk

About Blaze Information Security

Blaze Information Security is a privately held, independent information security firm born from years of combined experience. With presence in South America and Europe, Blaze has a team of senior analysts with past experience in leading information security consulting companies around the world and a proven track record of published security research.

E-Mail: [email protected]
Wildfire Labs blog
Twitter
Github

PGP key fingerprint: 9F8C 5552 C6A3 35F8 76E3 9A0C 09BD AA79 93E7 AE65

Do you have questions? Let's talk.

Get in touch with our cybersecurity experts

Read More