Quantum Vegetarian Bacon Sammich Edition
Social Media Bridges
Post 6 of 8
Sneakysneaks ๐ฅท
Just like how Ledger Nano claimed they have NO BACKDOOR for hackers, they (like Mastodon) decided to open their FRONTDOOR to the white hats instead
In 2023, the Mozilla Foundation contracted Cure53 to perform penetration testing on Mastodon's software, in preparation to bridge Mastodon with Mozilla's community. The testing "discovered" "several vulnerabilities", most notably one called "TootRoot" which would have enabled arbitrary code execution and another that would have enabled cross-site scripting attacks through oEmbed cards
Arbitrary Code Execution (ACE): an attacker's ability to run any commands or code of the attacker's choice on a target machine or in a target process. ACE vulnerability is a security flaw in software or hardware that would allow arbitrary code execution to hijack any or all Mastodon nodes/servers
Cross-Site Scripting (XSS): security vulnerability that can be found in some web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users and may be used by attackers to bypass access controls
oEmbed: an open source form that enables embedding content from a website into another page. For example, Twitter uses it to embed tweets into blog posts. Squarespace, WordPress, Drupal, and LinkedIn all happen to embed content using oEmbed
While these vulnerabilities were supposedly "patched" in July 2023, we know that this patch was actually a test to prepare Mastodon's servers to eventually allow "white hat hackers" to hijack all of their nodes/servers in order to push specific content to individual users in 2024 Social Media Bridges as well as block nefarious servers and users
https://arstechnica.com/security/2023/07/mastodon-fixes-critical-tootroot-vulnerability-allowing-node-hijacking/
For example, in September 2023, the following bugs were discovered:
- Attackers can spoof domains they do not own
- By crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon, which can be used to perform confused deputy attacks if the server configuration includes ALLOWED_PRIVATE_ADDRESSES to allow access to local exploitable services
- Under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing unescaped HTML to execute in the browser. The impact is limited thanks to Mastodon's strict Content Security Policy, blocking inline scripts, etc. However a CSP bypass or loophole could be exploited to execute malicious XSS
https://github.com/mastodon/mastodon/security/advisories/GHSA-2693-xr3m-jhqr
So WHOSE private addresses are being allowed?
๐ฑ Stellar & QFS Training App



