Perimeter
7/30/2009
12:26 PM
Sara Peters
Sara Peters
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.The charmingly dreadlocked Moxie Marlinspike delivered a fascinating presentation in which he showed us four new ways his SSL Sniff and SSL Strip tools could be suped up to make SSL certificates less trustworthy than ever.

Several months ago Marlinspike created SSL Strip, a tool that exploits a Web vulnerability and behaves as a man in the middle, slipping into the middle of an https redirect. So when a user leaves an http session and thinks they're being sent to an https session, the attacker has actually sent them somewhere else. The user thinks they've begun operating in a secure session, but in actuality they never made it to the legitimate SSL-encrypted site. A legitimately secure site and a "stripped" site were almost indistinguishable.

Yesterday Marlinkspike showed a demo in which the legitimate and exploited sites were entirely indistinguishable. Marlinspike showed how to overcome even the two significant hurdles that would, theoretically, prevent his attacks -- software updates and OCSP (the Online Certificate Status Protocol). The update problem was sidestepped by going after the update server itself--thereby achieving the access privileges necessary to make updates silent. The OCSP trouble required different trickery that I won't get too deeply into here, but suffice it to say that all it required was to send a milquetoast error message -- "try again later."

The heart of the problem though is the X.509 standard, which Marlinspike called "a total nightmare" and security rockstar Dan Kaminsky later called "remarkably fragile." Ultimately X.509 is fraught with ambiguity, which means that everyone is implementing their crypto somewhat differently -- and that makes life complicated for both browsers and certifying authorities (CAs). They can't lower the boom on poor, insecure configurations without running the risk of demolishing the authentication systems of many, many, many, sites.

The good news is that, according to Kaminsky, browser vendors, CAs and security researchers alike are working together to start repairing these problems -- first trying to patch up the X.509 standard, then deciding upon a better authentication method (possibly leveraging DNSSEC), then (fingers crossed) figuring out how to move from X.509 to a brave new world.

In entirely unrelated news...Dmitri Alperovitch described the nationalistic yet capitalistic mindset of Russian organized crime in a clearer way than I'd heard it put before: Money is the motive. Nationalism is the rationalization.

Sara Peters is senior editor at Computer Security Institute. Special to Dark Reading. Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6477
Published: 2014-11-23
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4...

CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-8626
Published: 2014-11-22
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding...

CVE-2014-8710
Published: 2014-11-22
The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?