Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ AppCache Scope Restricted

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š AppCache Scope Restricted


๐Ÿ’ก Newskategorie: Programmierung
๐Ÿ”— Quelle: blog.chromium.org

The Application Cache (AppCache) specification has been deprecated since December 2016 and in Chrome starting in version 79. In Chrome 70, AppCache was removed from insecure contexts. We plan to remove AppCache in Chrome 82. Prior to AppCache's removal in Chrome 82, we're announcing a security fix that introduces the concept of a manifest scope.

Beginning in Chrome 80 in January, 2020, the scope of the AppCache manifest will be restricted to the path it is served from. Previously, a manifest served from any location within a site's origin could override everything within that origin. For example, a manifest served from www.example.com/foo/bar/ would previously allow overriding any URLs within www.example.com. Now it will only allow overriding URLs beginning with www.example.com/foo/bar/, the scope of the manifest.

Does This Affect My Website?
To see if this affects your website, go to chrome://appcache-internals/ and compare the path of the manifest to the paths under File URL. Note that this change only affects "Intercept" and "Fallback" properties. (See the image below.)


You should also test your site using the command line feature flag. To do so:

  1. Launch Chrome 80 using the following command:

    google-chrome --enable-features="AppCacheManifestScopeChecks"
  2. Open chrome://appcache-internals/, find your manifest and remove it.
  3. Open your site so a new AppCache instance is created.
  4. Open chrome://appcache-internals/, verify your manifest appears as expected and parser version is set to 1.
  5. Go offline, then access your site so it's served from AppCache. Verify all pages load as expected.
Mitigations
The replacement technology for AppCache is the Cache API, which requires a service worker. For a shorter term mitigation, add the following HTTP response header to your manifest responses:


X-AppCache-Allowed: /

This header is new in Chrome 80 and will be supported until Chrome 82, which is our announced AppCache removal milestone. Please be aware that AppCache, like all Chrome features, makes use of the disk cache to fetch server responses, so any long-lived disk cache entries for a manifest must be cleared in order to pick up a server X-AppCache-Allowed header change.
...



๐Ÿ“Œ AppCache Scope Restricted


๐Ÿ“ˆ 59 Punkte

๐Ÿ“Œ Scope in JavaScript โ€“ Global vs Local vs Block Scope Explained


๐Ÿ“ˆ 32.08 Punkte

๐Ÿ“Œ [JS] The top-level scope is NOT always the global scope


๐Ÿ“ˆ 32.08 Punkte

๐Ÿ“Œ Major Browser Vendors to Restrict AppCache to Secure Connections


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ "Mass Triage Part 4: Processing Returned Files - AppCache\/Shimcache"


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ Mozilla Firefox up to 54 AppCache Fallback Hijacking privilege escalation


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ Mass Triage Part 4: Processing Returned Files โ€“ AppCache/Shimcache


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ Google Chrome prior 70.0.3538.67 AppCache HTML Page Sandbox privilege escalation


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ Google Chrome prior 70.0.3538.67 AppCache HTML Page Sandbox privilege escalation


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ Google Chrome prior 89.0.4389.72 AppCache Remote Code Execution


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ Microsoft Edge appcache Remote Code Execution [CVE-2021-21168]


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ CVE-2015-6767 | Google Chrome 47 AppCache use after free (BID-78416 / XFDB-108405)


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ Mozilla Firefox bis 54 AppCache Fallback Hijacking erweiterte Rechte


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ CVE-2015-6766 | Google Chrome 47 AppCache use after free (BID-78416 / XFDB-108404)


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ CVE-2015-6765 | Google Chrome 47 AppCache use after free (BID-78416 / XFDB-108403)


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ CVE-2019-5862 | Google Chrome prior 76.0.3809.87 AppCache HTML Page input validation


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ CVE-2020-6399 | Google Chrome prior 80.0.3987.87 AppCache HTML Page input validation (RHSA-2020:0514)


๐Ÿ“ˆ 25.65 Punkte

๐Ÿ“Œ New CloudLinux 7 Kernel Now in Beta, Disables Procfs Restricted Mode by Default


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ New CloudLinux 7 Kernel Now in Beta, Disables Procfs Restricted Mode by Default


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ YouTube Says Restricted Mode Blocks Mature Content, Not LGBTQ+


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ YouTube on Restricted Mode Blocking LGBTQ+ Content: Our System Is Flawed


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ UCOPIA Wireless Appliance Restricted Shell Escape


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ UCOPIA Wireless Appliance Restricted Shell Escape


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ [local] UCOPIA Wireless Appliance < 5.1.8 - Restricted Shell Escape


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ Hackers steal restricted information on F-35 fighter, JDAM, P-8 and C-130


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ OLG Bremen: Right reserved in a joint will to make amendments can be restricted


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ YouTube Fixes Restricted Mode Filtering Issue, Brings Back 12M Videos


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ Extreme EXOS 16.x/21.x/22.x exsh Restricted Shell Protection erweiterte Rechte


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ [papers] Linux Restricted Shell Bypass Guide


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ Linux Restricted Shell Bypass Guide


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ Apple iPhoneโ€™s USB Restricted Mode gives Feds a cracking headache


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ Apple OS Update Lifts Curtain on iPhone USB Restricted Mode


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ Apple USB Restricted Mode feature will make hard for law enforcement to crack devices


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ iOS 11.4.1-Update mit "USB Restricted Mode"-Sperroption ist da


๐Ÿ“ˆ 17.32 Punkte

๐Ÿ“Œ USB Accessory Can Defeat iOS's New "USB Restricted Mode" Security Feature


๐Ÿ“ˆ 17.32 Punkte











matomo