Wednesday, March 07, 2012

5% of websites have had at least 1 SQL Injection vulnerability without needing to login


During RSA Dave Aitel, CEO of Immunity, asked me a statistics question relating to website security. Dave asked, “What percentage of websites is WhiteHat seeing as vulnerable to SQL Injection — without needing to authenticate?” That last detail is important, especially in the era of mass blast SQL Injection worms and prolific bad-guy-scanner-use searching for victims of opportunity.

I didn’t have the number off the top of my head, would have to look it up in the WhiteHat Sentinel database to be certain, but my first impression was it’s probably around 5%. I thought so was because we’re currently tracking about 14% of all websites having had at least one SQL Injection vulnerability (slide 13). Restricting to non-auth would obviously drag the number down.

To Dave’s surprise, 5% was what he is measuring as well, as was as one other he asked. I asked WhiteHat Security’s resident data scientist, Bill Coffman, to provide the real figures.To first understand our data scope, WhiteHat Sentinel is used to perform continuous vulnerability assessments on thousands of publicly facing websites. 500+ companies in all, large and small, and across industries such as financial services, retail, healthcare, energy, etc. The large majority our vulnerability assessment are conducted in a logged-in state.

Fortunately, we offer a service line named Baseline Edition (BE), which does not authenticate. BE is generally for customers who only require a “baseline” level of testing comprehensiveness, usually deployed broadly across their entire website portfolio. So, Bill restricted our data set to only a BE covered websites, which ended up encompassing many hundreds.

Of all BE websites, created under WhiteHat Sentinel before March 2011, yielded 5%. That is, 5% of websites have had at least 1 SQL Injection vulnerability without needing to login!

We restricted the sampling to a year back to ensure the websites had all their scans properly configured and had enough time to complete over a long enough period. Newer sites are not in a stable state to be statistically representative.

There is one potential caveat in the data, which we can’t properly account for that is likely to move the percentage up. Just because an assessment is conducted in a logged-in state does not mean the URL that’s vulnerable to SQL Injection can’t be exploited while NOT logged-in — an authentication / authorization issue, which should up on our statistics report top ten.

So, those are our numbers. If you are in the website vulnerability assessment business, what are yours?


Tuesday, March 06, 2012

Tips for NOT getting Hacked on the Web


Following my TEDxMaui presentation, a great many every day people have been emailing, Facebook’ing, and Tweet’ing me asking for tips on how to keep themselves safe online. Safe from malicious software attacks, safe from their online account getting taken over, and safe from their PC getting hacked. This post is for them.

No one wants to end up like the guy on Flickr who had five years worth of photos deleted, like the woman whose personal email box was hacked and held for ransom, like the thousands on Facebook whose accounts have been taken over and friends scammed for cash thinking they are helping you out of a jam when really some miscreant is assuming your identity. Perhaps worst of all like the people whose computers were hacked into and an intruder quietly flipped on their video camera to record their most intimate moments and proceeded to toy with their lives.

Poor economic conditions being what they are, perhaps having your online bank account liquidated by organized criminals may not be all that bad relative to these poor people — even with no guarantee you’ll get your hard earned money back. The reality is all these things and more are painfully common and go largely undetected.

Don’t be fooled for a second into thinking antivirus companies are going to save you, nor a corporation’s generic we-take-security-very-seriously-we-promise-policy, and certainly not law enforcement. These guys get hacked just like everyone else and are completely overwhelmed by billions of dollars lost every year due to online fraud already. They are very unlikely to understand, help, or even investigate your particular situation.

The undisputable fact is you, and you alone, are the best defense against getting hacked and getting taken advantage of. Keep in mind that getting hacked is not act of nature like a flood, earthquake, or tsunami. Getting hacked can be avoided. The steps to do exactly I’m going to share with you are simple, won’t cost you a dime, are sometimes a little unconventional, but they are most definitely effective. These are the same things security pros do to protect themselves. There is no reason why you can’t use them too!

Must-Have Software

 1) Upgrade Microsoft Windows or Mac OS X

Outdated software is the enemy of online safety and security. Fortunately this process is easy and you should do this right now, even before reading the rest of this article.

If you use Microsoft Windows…

Fire up your Internet Explorer web browser and visit Microsoft Update. Just follow the instructions on the screen to update your system with the latest software. Next download and install Microsoft Security Essentials, which is their free antivirus software package.

If you use Mac OS X…

All you have to do is click the Apple logo in the top left of your screen, select “Software Update…”, and then follow along.

 

2) Install a modern Web browser. Better yet, pick two!

You do know what a Web browser is right? Not everyone does. A Web browser is the software you use to surf the Web and visit websites like Facebook, Gmail, and Amazon. ChromeFirefox, and Internet Explorer are all solid and speedy Web browsers. The choice between them is largely personal preference.

If you already use one of these browsers, great, just make sure you are running the very latest version. Nothing brings a smile to a malicious hackers face like a victim with an ancient browser, such as Internet Explorer 6. It’s like a professional car thief walking up to a car without any anti-theft devices installed, gone in sixty seconds.

If you are a Windows and Internet Explorer user, and you performed step 1, you are all set. If you use Chrome, click the wrench in one of the browser windows and select “About Google Chrome.” If you need to update, the “Update Now” button will allow you to click it. For Firefox, it’s the same process as Chrome. Go to the “About Firefox” window, and if you need to update a button to press will be there.

Next, install a different browser from the recommended list, because you’ll need two for the safest browsing experience.

 

3) Install ad blocking extensions

If you’ve chosen Chrome or Firefox as one of your Web browsers, you are going to absolutely love ad blocking extensions like Adblock and Adblock Plus. These extensions allows you to surf the Web without ads, which also has a powerful benefit of increasing security and privacy automatically.

Malicious software often infects computers through viewing or clicking of online advertisements. When you actually want to see ads, don’t worry, it is really easy to turn on and off when you want.

For extra privacy, consider installing either Disconnect or Ghostery extensions. Essentially all online advertisements are “trackers,” which stalk you around the Web profiling your online habits, but not all “trackers” are advertisements. Disconnect and Ghostery block these invisible trackers and aid in protecting your online privacy.

 

Online Street Smarts

Think of the Web like an inner city. There are some really great places to visit, enjoy nice meals, and hang out with friends. However, as in any inner city with over one billion people, there will be some shady characters lurking around trying to scam and rob you. You have to keep your guard up. The problem is the digital world makes it tough to see and therefore avoid dangerous street corners. I’ll show you how.

 

4) Your weekend browser and your commuter browser

Many people drive one car every day to work and keep a nicer one in the garage ready for the weekends or a night on the town. Your two browsers should be used the same way. Choose one, your commuter browser, for every day surfing. Read news, play games, watch YouTube, whatever. Just don’t login to anything you consider really important! That is what the other browser is for.

When you bank, upload photos, check your WebMail, trade stock, or buy anything — fire up your weekend browser. This is the browser you protect by going directly to a website, typing the address into the location bar or using a bookmark, and nowhere else. Close it down when you are done.

Then if anything, or anyone, attacks your commuter browser when you are exploring the Web, it is no problem because you’ve never done anything important with it. You don’t take your weekend car down to a bad part of town right?

 

5) Be careful of what you download and paranoid of what you install

After going through all the trouble of making sure you have the latest software, and compartmentalized your risk with two browsers, don’t go and install something evil that will ruin everything. Downloads are like narcotics peddled by drug dealer. Just say no! They might make you feel good temporarily, but long term the effects are deadly.

The bad guys are extremely clever too. They actually disguise their “product” as antivirus software to help protect your computer. HAH! The also might say you need to install a special codec or something to watch the latest celebrity sex tape. Don’t fall for that. Go to YouTube, Break, or some other major video sharing site instead. Email attachments also need to be treated with paranoia, especially from people you know, because they might not have been as cautious as you.

 

6) Make your passwords hard to guess

You wouldn’t have the same key for your home, car, office, safe, etc. For the same reason you shouldn’t use the same password for all your online accounts. Pick passwords that are hard to guess, not found in the dictionary, six characters or more in length, and sprinkle in a number or special character for good measure. Something like: y77Vj6t or JX0r21b

Anything more than having two or three passwords like this gets to hard to remember, so you have a choice to make.

a) Write down your password on a piece of paper

Use a small sheet of paper that fits in your wallet or maybe index cards locked in a desk drawer. It is much easier and safer for people to protect physical paper than data on a computer. Keep two copies around just in case one is lost. Unfortunately storing passwords on paper is not terribly convenient, so you might consider a password manager instead…

b) Use a password manager

Password managers, like LassPass or 1Password, are software that stores your passwords in a safe place on and encrypts the data. Not as secure as writing them down, but that’s the trade-off you make. The password managers that are built into the Web browsers are not terribly safe or secure, at least not nearly as much as their desktop cousins.

 

7) BACKUP! Your computer, blog, email, photos — everything

Sh*t happens. Technology is imperfect, we all make mistakes, computers crash, and bad guys sometimes get lucky.  Hope for the best, but prepare for the worst. Keep copies of your photos, email, blog posts and other treasured digital possessions on a CD/DVD, thumb drive, or even local hard drive. Disk space is way cheap these days so there is no reason not to make the investment.

If you are an Apple fan like me the Time Capsule (DSL Router / Backup device) and MobileMe are excellent choices. There are also several other solid and inexpensive online backup providers including MozyBackblaze, and Dropbox. One cannot stress the importance of backups. Should disaster strike, you be really glad that you took the time.

 

Summary

That’s it! You have your survival kit of everything you need to keep your information safe. The cyber criminals out there on the Internet mean business. They are in it for the money, your money. They pride themselves on being well informed and ahead of the curve, which is exactly what is needed to NOT become a victim to online fraud and other nastiness. Being just a little bit safer and secure than the rest of the masses doing little to nothing to protect themselves makes all the difference.

Tuesday, February 14, 2012

Top Ten Web Hacking Techniques of 2011


Every year the Web security community produces a stunning amount of new hacking techniques published in various white papers, blog posts, magazine articles, mailing list emails, etc. Within the thousands of pages are the latest ways to attack websites, Web browsers, Web proxies, and so on. Beyond individual vulnerability instances with CVE numbers or system compromises, we’re talking about actual new and creative methods of Web-based attack. The Top Ten Web Hacking Techniques list encourages information sharing, provides a centralized knowledge-base, and recognizes researchers who contribute excellent work.

 The Top Ten

  1. BEAST (by: Thai Duong and Juliano Rizzo)
  2. Multiple vulnerabilities in Apache Struts2 and property oriented programming with Java (by: Johannes Dahse)
  3. DNS poisoning via Port Exhaustion (by: Roee Hay and Yair Amit)
  4. DOMinator – Finding DOMXSS with dynamic taint propagation (by: Stefano Di Paola)
  5. Abusing Flash-Proxies for client-side cross-domain HTTP requests (by: Martin Johns and Sebastian Lekies)
  6. Expression Language Injection (by: Stefano Di Paola and Arshan Dabirsiaghi)
  7. Java Applet Same-Origin Policy Bypass via HTTP Redirect (by: Neal Poole)
  8. CAPTCHA Hax With TesserCap (by: Gursev Kalra)
  9. Bypassing Chrome’s Anti-XSS filter (by: Nick Nikiforakis)
  10. CSRF: Flash + 307 redirect = Game Over (by: Phillip Purviance)

How the winners were selected…

 

Phase 1: Open community voting (Ballot) [COMPLETE]

From of the field of 51 total entries received listed below, each voter (open to everyone) ranks their fifteen favorite Web Hacking Techniques using a survey. Each entry (listed alphabetically) get a certain amount of points depending on how highly they are individually ranked in each ballot. For example, an each entry in position #1 will be given 15 points, position #2 will get 14 point, position #3 gets 13 points, and so on down to 1 point. At the end all points from all ballots will be tabulated to ascertain the top fifteen overall. And NO selecting the same attack multiple times! :) (they’ll be deleted)

Voting will close at the end of the day this Monday, February 20.

[CLOSED] The more people who vote, the better the results! Vote Now!

 

Phase 2: Panel of Security Experts [COMPLETE]

From the result of the open community voting, the top fifteen Web Hacking Techniques will be voted upon by panel of security experts (to be announced soon). Using the exact same voting process as phase 1, the judges will rank the final fifteen based of novelty, impact, and overall pervasiveness. Once tabulation is completed, we’ll have the Top Ten Web Hacking Techniques of 2011!

Voting will close at the end of the day on Sunday, February 26.

Soon after the winners will be announced!

Good luck everyone

 

The Final 15:

Hundreds of votes were cast during the open vote — a great turn out. Thank you everyone for taking the time! 44% of the respondents were self-described “Breakers,” follow by 22% “Defenders,” 16% “Builders,” and 17% did not specify. There was a very smooth distribution of points totals across the range of entries. Clearly everyone had their favorites. Of course we saw a lot of ballot stuffing action, which required a substantive amount of clean-up, but when ranking a Web hacking techniques’ its kind of what you expect :) This is exactly why we have a final 15 process first, so the top ten outcome isn’t negatively affected. Any entries that obviously don’t belong in the top ten are easily eliminated during the “Panel of Security Experts” phase. Now it’s the judges turn to have their say!

  1. Abusing Flash-Proxies for client-side cross-domain HTTP requests
  2. Abusing HTTP Status Codes to Expose Private Information
  3. Autocomplete..again?!
  4. BEAST
  5. Bypassing Chrome’s Anti-XSS filter
  6. CAPTCHA Hax With TesserCap
  7. Cookiejacking
  8. CSRF: Flash + 307 redirect = Game Over
  9. DNS poisoning via Port Exhaustion
  10. DOMinator – Finding DOMXSS with dynamic taint propagation
  11. Expression Language Injection
  12. Java Applet Same-Origin Policy Bypass via HTTP Redirect
  13. JSON-based XSS exploitation
  14. Multiple vulnerabilities in Apache Struts2 and property oriented programming with Java
  15. Session Puzzling (aka Session Variable Overloading)

The Big List:

  1. Abusing Flash-Proxies for client-side cross-domain HTTP requests [slides]
  2. Abusing HTTP Status Codes to Expose Private Information
  3. Autocomplete..again?!
  4. BEAST
  5. Bypassing Chrome’s Anti-XSS filter
  6. Bypassing Flash’s local-with-filesystem Sandbox
  7. CAPTCHA Hax With TesserCap
  8. CSRF with JSON – leveraging XHR and CORS
  9. CSRF: Flash + 307 redirect = Game Over
  10. Close encounters of the third kind (client-side JavaScript vulnerabilities)
  11. Cookiejacking
  12. Cross domain content extraction with fake captcha
  13. Crowd-sourcing mischief on Google Maps leads customers astray
  14. DNS poisoning via Port Exhaustion
  15. DOMinator – Finding DOMXSS with dynamic taint propagation
  16. Double eval() for DOM based XSS
  17. Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames)
  18. Excel formula injection in Google Docs
  19. Exploitation of “Self-Only” Cross-Site Scripting in Google Code
  20. Exploiting the unexploitable XSS with clickjacking
  21. Expression Language Injection
  22. Facebook: Memorializing a User
  23. Filejacking: How to make a file server from your browser (with HTML5 of course)
  24. Google Chrome/ChromeOS sandbox side step via owning extensions
  25. HOW TO: Spy on the Webcams of Your Website Visitors
  26. Hidden XSS Attacking the Desktop & Mobile Platforms
  27. How To Own Every User On A Social Networking Site
  28. How to get SQL query contents from SQL injection flaw
  29. How to upload arbitrary file contents cross-domain (2)
  30. JSON-based XSS exploitation
  31. Java Applet Same-Origin Policy Bypass via HTTP Redirect
  32. Kindle Touch (5.0) Jailbreak/Root and SSH
  33. Launch any file path from web page
  34. Lotus Notes Formula Injection
  35. Multiple vulnerabilities in Apache Struts2 and property oriented programming with Java
  36. NULLs in entities in Firefox
  37. Rapid history extraction through non-destructive cache timing (v8)
  38. Session Puzzling (aka Session Variable Overloading) Video 1234
  39. SpyTunes: Find out what iTunes music someone else has
  40. Stealth Cookie Stealing (new XSS technique)
  41. Stripping Referrer for fun and profit
  42. SurveyMonkey: IP Spoofing
  43. Temporal Session Race Conditions Video 2
  44. Text-based CAPTCHA Strengths and Weaknesses
  45. The Failure of Noise-Based Non-Continuous Audio Captchas
  46. Timing Attacks on CSS Shaders
  47. Tracking users that block cookies with a HTTP redirect
  48. Using Cross-domain images in WebGL and Chrome 13
  49. XSS in Skype for iOS
  50. XSS-Track as a HTML5 WebSockets traffic sniffer
  51. HashDOS: Effective Denial of Service attacks against web application platforms

Sunday, February 12, 2012

Web Browser Defense-in-Depth: 3 Layers is Good, 5 is Better

 

A simple example of Defense-in-Depth is protecting a PC from remote compromise by keeping the machine up-to-date on patches AND surrounding it with a firewall. Should a firewall fail for some reason, the PC remains resilient against remote exploitation because it is properly patched. If the PC falls behind on its patches, which frequently happens, a well-configured firewall protects against compromise by denying inbound connections.

Web browsers also have a notion of Defense-in-Depth, but the major vendors don’t ship them with as many layers as they could (or should?). By my count, Chrome installs with three layers. Fortunately, with a simple configuration change and installing a specific add-on, anyone can add two more layers of defense and dramatically improve their protection against browser exploitation and PC malware infection. Before discussing the specifics, we should first describe the attack pathology we’re defending against.

A very common way malware is propagated is by visiting “infected” websites. Infected websites could be hosting the malware package itself, or including it as part of third-party Web page content, like an advertisement. When a browser, such as Chrome, visits an infected website it could be exploited via an unpatched software flaw. It is also possible, if not typical, for the exploit to target an installed browser plugin like Flash. We pick on Chrome and Flash only because they provide extra layer of defense that the other browsers and other extensions including Java and Quicktime do not. A sandbox.

To successfully compromise a Chrome browser with five layers of Defense-in-Depth, the attacker must overcome:

1) Phishing and malware detection

Phishing and malware detection,” enabled by default in Chrome, gives users an interstitial warning that, “Visiting this site may harm your computer.” This is essentially a curated blacklist of dangerous websites and is by no means ever complete. For an attacker to bypass the phishing and malware layer of defense, one of three things would have to take place:


  • Their victim would have to manually disable this setting in the preferences, which is unlikely yet possible.
  • Their victim must REALLY wants to see the dancing monkey on the next screen and is willing to risk infection to do so. As we know, people click past warning screens all the time.
  • The attacker plants their malware in a location that evades, even temporarily, detection by Google’s and their partners. Certainly possible.

It is prudent to assume one of these three scenarios may transpire and the layer of defense will fail, so we need another.

 

2) Ad Blocking

Instead of setting up their own infected websites, or compromising otherwise legitimate websites and injecting them with malware, malware purveyors commonly purchase advertising impressions and use them to mass distribute their wares to a potential victim. Malicious advertisements are often referred to as “malvertisements.” Millions of malvertisements can be purchased for mere dollars and this is where ad blocking, with extensions such as Ad Block and Adblock Plus, prove highly effective.

Ad blocking extensions, which do not ship with a mainstream Web browser, prevent HTTP requests from being sent to well-known advertising networks and downloading potentially malicious content. If your browser doesn’t download a malvertisement, then it obviously can’t be exploited by it. With ad blocking, a Web browser may remain unscathed even while visiting a website currently infected by malvertisements. So, not only does ad blocking make for a more pleasant user experience, it makes surfing the Web much safer!

Since ad blocking is itself a black list, a malicious ad could potentially slip through, and if so, another layer of defense is necessary.

 

3) Plug-in Blocking

As mentioned earlier, malware exploits are well-known for targeting Web browser plug-ins/extensions such as Flash, Java, Quicktime, and others that auto-execute by default when called by a website. Theoretically, if extensions did not auto-execute, extensions could also not be auto-exploited. To make this theory a reality, in Chrome you can disable the auto-execution of plug-ins.

  • Wrench > Preferences
  • Under the Hood > Privacy
  • Click the “Content Settings…” button
  • Scroll down to “Plug-ins” and select “Block all.”

Now for Flash, Java, or Quicktime, etc files to play, a user must specifically allow it with additional clicks.

Normally, extension-based exploits that lead to malware are embedded invisibly so their victim doesn’t see them, especially in malvertisements, which means there is little reason to click to allow them to play. This also means if there is a movie on the screen, or something else that you really want to see, it should be safe enough to allow — but not always. So, something malicious might still find a way to load and another layer of defense is necessary.

 

4) Software Security & Auto / Silent  Patching

Google (maker of Chrome), and Adobe (maker of Flash) have invested extraordinary amounts of resources to improve the security quality of the software they ship. Despite their best efforts, software flaws will remain, often found by outsiders, and their products will need to be patched frequently. Patching frequency leads to patch fatigue and without help, every user falls behind eventually.

To help, Google and Adobe ship with an integrated auto and/or silent update feature for their software. Chrome and Flash regularly check on their own accord if they need to be patched so users don’t have to remember. Doing so has proved measurably effective in keeping users up-to-date on their patches and by extension, secure. However, it is possible for attackers to slip an exploit within the window of time before a would-be victim patches, or they may leverage a zero-day exploit for which no patch exists. This brings us to our last layer of defense-in-depth.

 

5) Sandbox

A sandbox is a software security wrapper that encompasses both Chrome and the Flash plug-in in a highly-restricted, low-privilege environment. Java and Quicktime do not have a sandbox, but they should. Firefox is working on theirs. Should an attacker leverage an unpatched exploit, or one for where no patch exists, they’ll need another exploit that allows them to breach the sandbox. This means the attacker will need two exploits instead of just one. This is another significant hurdle to overcome because with present security offense knowledge, sandboxes are notoriously difficult to escape.

 

For an attacker to succeed in infecting a users PC with malware via the Chrome browser, they’ll have to somehow overcome five layers of Defense-in-Depth…

First, the attacker must keep their malware off black-listed sites or have the malware in a location attractive enough where the victim is convinced to manually ignore all the big red warning signs.

Second, upon landing on the infected Web page the malware must NOT come from a well-known advertising network, but if so, the victim must be enticed to specifically allow the ad to load.

Third, should the malware try to exploit an extension, the victim must manually allow the extension to load, and the visible content must be attractive enough to convince them to do so.

Fourth, the attacker’s exploit must be newer or faster than Chrome and Adobe’s patch management system, or they’ll need to use a zero-day vulnerability.

Lastly, that attacker will need to exploit another vulnerability to escape the sandbox. Then, and only then, after bypassing all five layers of Defense-in-Depth will an attacker be able to infect a user’s PC with malware.

Collectively, when considering all these layers, Chrome users should be able to click on anything on a Web page that they want, which is the nature of the Web, and not become infected with malware. Of course there are several more speed bumps and layers to be added with other configuration settings and add-ons, but with these five, everyone can do it easily.

 

So, block all extensions and install ad blocking software. Happy clicking!

Wednesday, February 08, 2012

A Single-Site Browser’s impact on XSS, CSRF, and Clickjacking

 

Practically no one in the marketplace offers SSBs, you have to build them yourself. When you think about it though, an SSB is functionally similar to a mobile application often provided by service providers very much like these. Often enough, a mobile app is basically a browser without a location bar, rendering a stripped down HTML/Javascript version of their website. SSBs are also very interesting from a security perspective as they have a profound impact on Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Clickjacking attacks.

Hypothetically, let’s say I’m an average online user. My “important” online accounts are Yahoo Mail (email), Facebook (social network), and Bank of America (bank). These are the online accounts I REALLY don’t want hacked. I’m disciplined to only use these services, and more importantly, log-in to them with their respective SSB. All my other promiscuous Web surfing is conducted with a general purpose Web browser like Chrome, Firefox, and Internet Explorer.

Next, let’s consider a common attack flow for XSS. Assume I’m logged-into Twitter’s website with Chrome, and I click on a link from someone I follow — you know one of those shortened link things that are impossible to know if they’re safe. That link is a disguised (reflected) XSS attack targeting Yahoo Mail, Facebook, or Bank of America, aka the accounts I care about. If the XSS vulnerability is located on an authenticated section of the website, more than likely, I’ll get redirected and asked to log-in. Obviously I’ll know not to enter my username and password because that is only for that websites SSB. So, I’m safe and not auto-hacked.

If the vulnerability does NOT require authentication, I’ll get XSS’ed. While the attacker has a control over my browser, at least temporarily, he can’t steal my authenticated session cookies because they don’t exist on this browser. Unless I break my rule of logging-in without my SSB my “important” accounts remain safe.

What about CSRF? While using a general purpose Chrome browser I click on some random link, could be on a blog post, message board, or news story. This link sends my browser to a malicious website that attempts to CSRF me on Yahoo Mail, Facebook, or Bank of America. Chrome can always be forced to send forged HTTP request to whatever target website, the nature of CSRF, but since I’m not authenticated nothing will happen that will compromise or even adversely affect my “important” accounts. The exact same is true for a Clickjacking attack. Any XSS, CSRF, or Clickjacking payload a bad guy chooses to deploy is limited to unathenticated attacks, which can still be damaging, but the accounts I care about remain safe.

Now let’s assume I’m operating within an SSB on Yahoo Mail, a website that consumes and redistributes user-supplied content in the form of email. User-supplied content, email, could include some form of HTML/Javascript. Should that content execute Javacript inside the SSB where I’m logged-in to Yahoo, technically a persistent XSS vulnerability, the bad guy can do some real damage. The security benefits of an SSB in this context with respect to XSS are more limited. Technically the XSS payload can do anything I can do (ie read, send, delete email). Data exfiltration, such as stealing session cookies which can lead to account compromise, may also take place via the same mechanisms (email). What the attacker can’t do is chain multi-site XSS attacks.

Keep in mind, though, that allowing users to send HTML/Javascript content to each other is an inherently dangerous feature to begin with and fortunately it is not all that common on the highly trafficked websites outside of WebMail providers. For example, Facebook and Bank of America do not offer this functionality. As a result, persistent XSS vulnerabilities like the one previously described are rare.

Another beneficial aspect of SSBs is that if I click on an off-website link, it’ll simply open a new tab in my default general purpose browser.  Any XSS, CSRF, or Clickjacking attack an off-website link tries is now separated from my SSB. That’s huge! However, if the link is on-website then I have to be careful as it could be a non-persistent XSS attack and do everything the early mentioned persistent XSS vulnerability could. A possible exception being calling in additional Javascript payload.

When everything is considered, the only time I can get my accounts compromised by XSS, CSRF, or Clickjacking is while I’m within the SSB. This dramatically cuts down my risk profile when traversing the Web. Suddenly general purpose browsing with Chrome, Firefox, and Internet Explorer become safer because sessions are separated by desktop application boundaries.

Tuesday, January 24, 2012

Who Would Want to Take Down the Internet?

 

To break this down we’ll use Mikko Hypponen’s TED talk as a framework. Mikko did a fine job categorizing and articulating the three main types of online attackers. They are cyber-criminals, hacktivists, and national-state. While the hacking techniques they use might be very similar to each others, each group has a unique set of motivations that drive their actions.

Hacktivists, such as Anonymous, LulzSec and others are among those who leverage hacking skills as a means to promote a social or political message — a form of protest if you will. A hacktivist might deface websites, publish stolen sensitive data, perform targeted Denial of Service attacks, but by enlarge their agenda does lead them to take down the Internet. Quite the contrary. If hacktivists disrupted the Internet, they also couldn’t spread their message, nor could others receive it and join the protest. Not to mention hacktivists are notoriously heavy supporters of the Internet, a free and open Internet.

Cyber-criminals, all they want is to make money. As much money as they can get their hands on. Cyber-criminals will hack their way into online accounts, directly or via compromised end-user PCs, and steal whatever money and data of value there is. Cyber-criminals also may Denial of Service a website to extract some extortion money, but just like the hacktivists, taking down the Internet would only obstruct their ability to profit. If the Internet went down, it would actually cost them money as they would not be able sell access to their botnet farms.

This leaves us with national-state, a type of online attacker that is government backed, whose mission is the theft of intellectual property, intelligence gathering, and surreptitious command-and-control over as many critical systems as possible. National-state hackers would also not seem to want to take down the Internet because it would directly prevent them from continuing their mission, especially when their targets are other countries. They’d lose their surveillance capabilities. However, there are exceptions here, two very particular scenarios where national-state and taking down the Internet makes sense.

In the first scenario, a national-state attacker would take down an enemy countries Internet access as part of an active and kinetic military conflict. The Russia v. Georgia conflict back in 2008 serves as a good example. Russia was accused of attacking Georgian government websites in a cyber war to accompany their military bombardment.

In the second scenario, when national-state enemy is domestic in origin (i.e. the people), then taking down or severely limiting Internet access for the entire country can be used to suppress citizen dissent. There are reports of this having occurred in Egypt and Iran — massive surveillance, disruption of communication, and censorship.

So when you get right down to it, the only attacker with motivation to “take down the Internet” is government backed. Then in one of the two scenarios, if your Internet goes down your government will be responsible. For myself, as one always considering the most pressing day-to-day threats to Internet security, I’m less concerned if the Internet can be taken down, but what happens when it stays up.