Apparently this was fixed server-side and does not require any update to the client. However the default version on addons.mozilla.org is very old for some reason, so if you are running 3.x it wouldn't hurt to download the latest. You can get it either from LastPass's website directly or from https://addons.mozilla.org/en-US/firefox/addon/lastpass-pass...
The 3.x is still updated, but they're replacing it soon. 4.x is a WebExtension, with a different UI. See https://blog.lastpass.com/2017/03/plans-to-retire-the-lastpa... for details.
LastPass RCE vulnerability fixed
11–20 of 188 posts
Re: LastPass RCE vulnerability fixed
#12I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
Re: LastPass RCE vulnerability fixed
#13Earlier quoted context omitted.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
same here. Trialling Dashlane, but not quite convinced yet..
Re: LastPass RCE vulnerability fixed
#14I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
Re: LastPass RCE vulnerability fixed
#15Earlier quoted context omitted.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
same here. Trialling Dashlane, but not quite convinced yet..
Re: LastPass RCE vulnerability fixed
#16Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.
Every member of Google's Project Zero team is individually more capable and productive than entire teams of consultants at the best security firms.
Re: LastPass RCE vulnerability fixed
#17"They also said they couldn't get my exploit to work, but I checked my apache access logs and they were using a Mac. Naturally, calc.exe will not appear on a Mac."
Re: LastPass RCE vulnerability fixed
#18Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.
Well, this is Project Zero, the security researchers working there are highly competent, but I do agree this guy is amazing. I wonder what kind of methodology do they use to even come up with these attacks.
1. They have a phenomenal intuition for where developers get lazy, tired or simply incompetent in security-sensitive code,
2. They have, in aggregate, a vast knowledge and understanding of past vulnerabilities and how those might be repeated elsewhere or imperfectly patched,
3. They practice a lot and they read a lot (i.e. relevant research, etc). It might be more accurate to say that they have a lot of practice because of their work, not that they actively practice outside of work.
4. They are good at the general process of security research - long hours of mostly dull, complex research interspersed with brief eureka moments and bouts of euphoria.
They're an extraordinary team, for sure.
Re: LastPass RCE vulnerability fixed
#19Earlier quoted context omitted.
same here. Trialling Dashlane, but not quite convinced yet..
If you're interested in an open source option that compares quite well to the LastPass feature-set, check out bitwarden: https://bitwarden.com/ (note: I am the lead developer).
Only issues I have right now are:
- No app-fill on Android.
- No auto-fill (have to manually click the icon and select an account).
- When using Firefox the extension periodically logs out for no apparent reason.
- There's no address/wallet stuff so I actually have to pull out my credit cards.
Other than that it works pretty well.
Re: LastPass RCE vulnerability fixed
#20Earlier quoted context omitted.
The high number of vulnerabilities that keep being found in LastPass (including some that are not publicly disclosed) forced me to jump ship a while ago.
Can you please provide some references to the "high number of vulnerabilities"? I've only heard of one or two, but those were promptly fixed.