Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


09:50 AM

Browsing the Intranet Problem

Many intranet threats could be resolved at the browser level, but solutions will require some baking

5:50 PM -- The recent Black Hat and DefCon conferences, which finally wrapped up last week, were rich with Web hacking. It was definitely a first for me, to see so many talks about Web application security -- an area of security that was previously seen as just a narrow niche of security. Now, after all has been said and done, I think there are a few good takeaways that browser companies need to chew on.

First, there are the attacks. DNS rebinding attacks were in full force at Black Hat. At least three talks mentioned this rather obscure and complex attack, which allows hackers to access IP-restricted content behind firewalls. In addition, I participated in a talk on hacking intranets without using JavaScript. Clearly, the intranet is no longer off limits just because a firewall is in place.

So what can we do about it? There’s been some talk about disallowing inbound requests through VPN tunnels to anything that’s not already authorized -- like access to an internal wiki or Webmail, for instance. That’s a pretty flawed mitigation technique, because those targets are often the exact ones the bad guys are after. This is a problem that needs to be solved at the browser level.

There are two ways to handle it at the browser. The first is to leverage the "zones" concept already used by Internet Explorer. The concept is that the Internet zone should never be able to access the intranet zone, but this separation can break some Web apps -- especially things like Google Desktop.

While most people would gladly give up Google Desktop to protect their intranet’s security, it does cause some grief and isn’t seamless. No doubt someone would cry antitrust if this becomes a blanket practice. You could simply whitelist applications or ports that should be allowed -- such as Google Desktop, which runs on a specific, high port.

The other way to fix the problem at the browser level is to allow hooks that plug-in manufacturers can use. Allowing antivirus vendors to do the detection on the browser company’s behalf makes a lot of sense, but because it wouldn’t be automatically built into the browser, it’s not ubiquitous. If the solution isn't everywhere, it doesn’t matter, because all a bad guy needs to do is wait patiently until he finds a target that isn’t protected.

It’s going to be awhile before we see a browser-oriented solution put in place. But at least the browser companies know it’s a problem and are working to find solutions.

— RSnake is a red-blooded lumberjack whose rants can also be found at Ha.ckers and F*the.net. Special to Dark Reading

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This gives a new meaning to blind leading the blind.
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-06-16
There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This issue affects: OTRS A...
PUBLISHED: 2021-06-16
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.
PUBLISHED: 2021-06-16
Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link vers...
PUBLISHED: 2021-06-16
Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a user to pass code through the provided search field. ...
PUBLISHED: 2021-06-16
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-5...