Attacking Web 2.0 at LinuxWorld

By Robert Vamosi, CNET News.com
Wednesday, August 08, 2007 12:29 PM

At LinuxWorld today, SPI Dynamic's senior security engineer, Matt Fisher, talked about the vulnerabilities of Web 2.0.

His talk, although not much different from that of his colleagues Billy Hoffman and Brian Sullivan last week at Black Hat, offered some new examples of what criminals are doing online, armed with little more than a desktop browser. Cross-site scripting attacks are the Number one threat, according to the Mitre organization, in part because they are so easy to do.

In particular, Fisher singled out social-networking sites. Because the site depends on user content, the site allows users to upload HTML code, and in most cases, any HTML code. Knowing this, Fisher said someone could put a malicious script code into a blog post where it would sit until someone came along and read it. What bad could possibly happen from that, you might wonder? Fisher said that when someone in a corporate environment opens it, the attacker can then execute code inside the corporate perimeter on the internal network.

If that attack is too passive, Fisher suggested another scenario. In this scenario an attacker embeds malicious JavaScript into a customer help ticket. The help ticket is archived inside the corporate network. Every time a customer-support technician opens the help ticket, the code infects his or her desktop, and potentially, the corporate network.

Unlike operating system vulnerabilities, which can be addressed with a patch, cross-site scripting attacks are not generic; they are specific to the Web application. The key to mitigating these attacks is to limit what end users can and cannot do on the site. That sounds simple, but newer Web 2.0 sites often do not check for common, even old-school methods of attack.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Mainsoft: Opening options for Java, .NET developers

Java

Mainsoft provides tools for running .NET code on the Java platform.


Read more »


Tags

  1. against
  2. antivirus
  3. apple
  4. asia
  5. asian
  6. attacks
  7. by
  8. critical
  9. cyber
  10. data
  11. flaws
  12. google
  13. issues
  14. malware
  15. microsoft
  16. online
  17. over
  18. pledges
  19. security
  20. software
  21. spore
  22. symantec
  23. threats
  24. uk
  25. updates
  26. us
  27. vista
  28. web
  29. windows
  30. word
 
Oracle SOA Business Software Centre
Many companies are recognizing the need to adopt standards in their efforts to build service-oriented applications.
Secure the "Next-Gen SOA Infrastructure" & "Bringing SOA Value Patterns to Life" whitepapers here

» Visit the Power Center
Increase performance with eco-technology innovations
Simplify your infrastructure and unify management, while lowering power and cooling costs of your datacenter.
» Maximum flexibility with powerful blade technolgy
» Bring new services and applications online faster
» Lower energy use and cost

Up close and personal with a merger

Blog thumbnail

What can you get for 13.9 billion buckaroos? For Hewlett-Packard, US$13.9 billion would allow you to buy your way into becoming the second biggest IT services company in the industry...... by Eileen Yu

Read more »