Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Rethinking Website Spoofing Mitigation
Newest First  |  Oldest First  |  Threaded View
tdsan
50%
50%
tdsan,
User Rank: Ninja
8/17/2019 | 7:54:52 AM
Re: A new way of looking at a problem,

Also, a token could be issued by the company to validate their authenticity, this would be stored on the customer's browser or computer to ensure they are working with the right organization. This ensures the data is sent to the right company, even if it was not, the domain providers could provide a pop-up to the user stating that this could be a nefarious or ill-advised action, do you want to proceed or not.

One of the other options I mentioned below (from the quote in our earlier discussion) would be to add a token to the site, this would allow the browser to determine if the site was valid by using a SHA256 hash, site descriptor, and purpose all built into this number. This could be used to ensure the site is not a compromised site or if it is a site they have visited before, the browser would determine that much in the same way we use certificates. 

For me, I go to a few sites on a regular for personal and business purposes. There are others but this would help to address the security issue, not all but at least some aspects). Also, we need to start migrating the DNS environment to specifically use DNSSEC and move away from IPv4. This would be much harder for hackers to penetrate defenses because we would secure DNS traffic, reduce MITM attacks, create truly secure connections using IPSec VPN AES256 connections (all built into the protocol - IPv6). We can start identifying where the attack derived from (1-to-1 connections using IPv6) and the token would help to validate the site with the help of ML (I wanted to reiterate the point listed below because ML was only one of the points brought up in the beginning phases of the discussion).



Tokenization is the future of business and personal transactions. Blockchain is looking into that as well.

T


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/14/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17637
PUBLISHED: 2020-07-15
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
CVE-2020-7292
PUBLISHED: 2020-07-15
Inappropriate Encoding for output context in McAfee Web Gateway (MWG) prior to 9.2.1 allows remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
CVE-2020-14511
PUBLISHED: 2020-07-15
Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).
CVE-2020-4100
PUBLISHED: 2020-07-15
"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtim...
CVE-2020-5765
PUBLISHED: 2020-07-15
Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional i...