The Register® — Biting the hand that feeds IT

Feeds

Password-keeper LastPass plugs up IE cache leak vuln

Quis custodiet ipsos custodes?

Supercharge your infrastructure

LastPass has patched a flaw that meant Windows versions of its password-management software were capable of leaking login credentials that had been auto-filled into fields by its password manager.

The bug – which affected Internet Explorer users on Windows only – meant that an attacker who managed to obtain a memory dump of Internet Explorer would be able to extract unencrypted password strings.

"This is the same sort of attack that we have written about frequently in the context of banking malware," writes security researcher Paul Ducklin on the Sophos security blog.

Pulling off the attack would normally require either physical access to a targeted machine or an attack involving the planting of malware on a mark's PC, a level of compromise that makes most security protections redundant.

LastPass resolved the issue with a security update that also comes with a variety of performance enhancements and other tweaks. The relevant portion of the advisory explains: "Resolved: Security issue with IE exclusively while logged in to LastPass only: Prevent IE from adding passwords to in memory decryption cache".

The security fix is one of 18 items in LastPass v2.5.0/1/2, which also offers improved synchronisation and support for upcoming versions of Windows 8 and Internet Explorer 11.

The issue was first unearthed by a reader of PC Mag (story here). ®

5 ways to prepare your advertising infrastructure for disaster

Whitepapers

5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: Hate phishing emails? You'll love DMARC
DMARC has been created as a standard to help properly authenticate your sends and monitor and report phishers that are trying to send from your name..
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Email delivery: 4 steps to get more email to the inbox
This whitepaper lists some steps and information that will give you the best opportunity to achieve an amazing sender reputation.

More from The Register

next story
Chaos Computer Club: iPhone 5S finger-sniffer COMPROMISED
Anyone can touch your phone and make it give up its all
Hundreds of hackers sought for new £500m UK cyber-bomber strike force
Britain must rm -rf its enemies or be rm -rf'ed, declares defence secretary
NSA in new SHOCK 'can see public data' SCANDAL!
What you say on Twitter doesn't stay on Twitter
UK's Get Safe Online? 'No one cares' - run the blockbuster ads instead
Something like Jack Bauer's 24 ... whatever it'll take to teach kids how to bat away hackers
Sweet murmuring Siri opens stalker vulnerability hole in iOS 7
'Siri, hand over my contacts and history now…'
Facebook allows full personal data ransack with Graph Search
Posts, updates, the lot. Our ad sales will boom. Mwu-ha-haaaa ... bitch
Would you hire a hacker to run your security? 'Yes' say Brit IT bosses
We don't have enough securo bods in the industry either, reckon gloomy BOFHs
London schoolboy cuffed for BIGGEST DDOS ATTACK IN HISTORY
Bet his parents wish he'd been playing computer games
prev story