Risk
10/31/2008
04:25 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Defense Intelligence Agency Fixes Risky Web Site Code

The presence of a call to execute JavaScript code that resides on a Statcounter.com server in Ireland provided a weak link in the security chain that could have been exploited.

The Defense Intelligence Agency Web site, until earlier this week, exposed job applicants to potential privacy and security risks because it included a link to JavaScript code hosted on a third-party Web site.

While there's no evidence that the site leaked personal information, the presence of a call to execute JavaScript code that resides on a Statcounter.com server in Ireland provided a weak link in the security chain that could have been exploited to provide potentially valuable foreign intelligence about future DIA personnel.

Security researcher Bipin Gautam sent an e-mail to the Full Disclosure security mailing list earlier this week outlining his concerns.

In a follow-up e-mail to InformationWeek, he explained the issue. "If a Web site includes third-party JavaScript like stat counters, advertisement scripts, [or] banners called from third-party servers, the Web site is at risk of having to rely on the third party as well for overall security assurance of its Web site," he said.

In an e-mail, Robert "RSnake" Hansen, CEO of SecTheory and contributor to TechWeb security site Dark Reading, confirmed that the DIA Web site was unnecessarily vulnerable.

"It definitely is an issue if the Web site StatCounter.com were ever to get under an attacker's control," he said. "The site itself is not HTTPS, so it's already vulnerable to man-in-the-middle attacks."

The presence of that third-party JavaScript call, said Hansen, "could give an attacker complete cross-domain read/write into dia.mil."

The DIA was made aware of the risk following Gautam's initial post.

"This code was brought to DIA's attention by individuals within the agency on Monday," said a DIA spokesperson via e-mail. "Upon further investigation, it was resident only on the one page and was determined to be superfluous coding from a previous page incarnation. The code was deleted and no longer resides on DIA servers."

In response to the suggestion by one participant on the Full Disclosure mailing list that the cookie files used by StatCounter.com might have violated federal guidelines, the DIA spokesperson said that the DIA used session cookies (not persistent cookies) for its employment pages only and that the rest of dia.mil is cookie-free.

The spokesperson said, "DIA has followed and continues to follow Department of Defense policy on cookie usage."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5427
Published: 2015-03-29
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read pa...

CVE-2014-5428
Published: 2015-03-29
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integratio...

CVE-2014-9205
Published: 2015-03-29
Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data.

CVE-2015-0528
Published: 2015-03-29
The RPC daemon in EMC Isilon OneFS 6.5.x and 7.0.x before 7.0.2.13, 7.1.0 before 7.1.0.6, 7.1.1 before 7.1.1.2, and 7.2.0 before 7.2.0.1 allows local users to gain privileges by leveraging an ability to modify system files.

CVE-2015-0996
Published: 2015-03-29
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive info...

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.