Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

5/20/2009
02:52 PM
John H. Sawyer
John H. Sawyer
Commentary
50%
50%

Educating Our Clients Is Part Of Our Responsibility

Have you ever had a client (or your own employer) say, "There's no way a user could hack our internal Web apps; they can't run anything but authorized applications like a Web browser and e-mail client." Happens all the time, right? Guess what -- you're not alone.

Have you ever had a client (or your own employer) say, "There's no way a user could hack our internal Web apps; they can't run anything but authorized applications like a Web browser and e-mail client." Happens all the time, right? Guess what -- you're not alone.Jeremiah Grossman has posted a list of the top eight reasons Web vulns aren't fixed on his blog, and Chris Eng has a great follow-up titled, "But That's Impossible!"

It's not uncommon to find organizations that take the ostrich-with-its-head-in-the-sand approach to security, hoping that if they ignore it, then it will go away. I think we've all run into those types of managers and/or clients, but what about issues where a lack of understanding of the problem and attack methods is what's leading the company to think they are more secure? Let's use a couple of the statements from the Veracode blog.

"That system isn't even exposed to the outside." -- This is a great starter because by now you all should know that this is a non-issue for attackers when other systems on the same network are exposed or internal users who access that system are also receiving e-mail and browsing the web. Can you say client-side exploit? Maybe something like a zero day exploit against Adobe Acrobat that phones home giving an attacker an interactive shell to then attack internal systems?

"You are using specialized tools; our users don't use those." -- You gotta love this one! I've blogged about weaponizing Firefox with some great add-ons. All it takes is a Web browser, or even telnet, to exploit a Web browser vulnerability. I'd love to see reaction of the person who made that statement when you display the contents of his database through SQL injection with nothing but Internet Explorer.

"We don't even link to that page." -- How many data exposures could be attributed to this misguided statement? Tools like Nikto have existed for years that enumerate directories on a Web server by running through a common list of directories. In fact, that's how Metasploit and a new script for Nmap work to detect servers vulnerable to the IIS WebDAV zero-day vulnerability. They make repeated requests to a Web server looking for common directories, send a request using the Unicode string to any directories found, and determine whether it's vulnerable based on the HTTP response code.

Oh, I could go on and on with examples, but what I want to leave you with is that we as security pros must realize it is our responsibility to educate the people who respond with statements such as those. Our reports should detail the vulnerability and the risk carried with it. We should also be able to explain it to our clients during a presentation or in a private meeting in a way that they can understand it and aren't left feeling insulted them. That last part can be difficult, but it's crucial to getting repeat business and recommendations.

John H. Sawyer is a senior security engineer on the IT Security Team at the University of Florida. The views and opinions expressed in this blog are his own and do not represent the views and opinions of the UF IT Security Team or the University of Florida. When John's not fighting flaming, malware-infested machines or performing autopsies on blitzed boxes, he can usually be found hanging with his family, bouncing a baby on one knee and balancing a laptop on the other. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
How Attackers Infiltrate the Supply Chain & What to Do About It
Shay Nahari, Head of Red-Team Services at CyberArk,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7843
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-7846
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-7847
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.
CVE-2019-7848
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Inadequate access control vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-7850
PUBLISHED: 2019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.