Top 10 Web hacking techniques of 2010 revealed
- 25 January, 2011 03:08
- Comments
A Web hack that can endanger online banking transactions is ranked the No. 1 new Web hacking technique for 2010 in a top 10 list selected by a panel of experts and open voting.
Called the Padding Oracle Crypto Attack, the hack takes advantage of how Microsoft's Web framework ASP.NET protects AES encryption cookies.
FROM THE SECURITY WORLD: Quirky moments at Black Hat DC 2011
If encryption data in the cookie has been changed, the way ASP.NET handles it results in the application leaking some information about how to decrypt the traffic. With enough repeated changes and leaked information, the hacker can deduce which possible bytes can be eliminated from the encryption key. That reduces the number of unknown bytes to a small enough number to be guessed.
The developers of the hack -- Juliano Rizzo and Thai Duong -- have developed a tool for executing the hack.
Padding Oracle was voted No. 1 by a voting process that included Ed Skoudis, founder of InGuardians; Girogio Maone, the author of NoScript; Armorize CEO Caleb Sima; Veracode CTO Chris Wysopal; OWASP Chairman and CEO Jeff Williams; security consultant Charlie Miller of Independent Security Evaluators; IOActive director of penetration testing Dan Kaminsky; Steven Christey of Mitre; and White Hat Security vice president of operations Arian Evans.
The ranking was sponsored by Black Hat, OWASP and White Hat Security, and details of the hacks will be the subject of a presentation at the IT-Defense 2011 conference next month in Germany.
Here are the rest of the top 10 Web hacks voted in the competition:
2. Evercookie -- This enables a Java script to create cookies that hide in eight different places within a browser, making it difficult to scrub them. Evercookie enables the hacker to identify the machine even if traditional cookies have been removed. (Created by Samy Kamkar.)
3. Hacking Autocomplete -- If the feature in certain browsers that automatically completes forms on Web sites (autocomplete) is turned on, script on a malicious Web site can force the browser to fill in personal data by tapping various data stored on the victim's computer. (Created by Jeremiah Grossman.)
4. Attacking HTTPS with Cache Injection -- Injection of malicious Java script libraries into a browser cache enables attackers to compromise Web sites protected by SSL. This will work until the cache is cleared. Nearly half the top 1 million Web sites use external Java script libraries. (Crated by Elie Bursztein, Baptiste Gourdin and Dan Boneh.)
5. Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution -- Gets around cross site request forgery defenses and tricks victims into revealing their e-mail IDs. Using these, the attackers can reset the victim's passwords and gain access to their accounts. (Created by Lavakumar Kuppan.)
6. Universal XSS in IE8 -- Internet Explorer 8 has cross-site scripting protections that this exploit can circumvent and allow Web pages to be rendered improperly in a potentially malicious manner.
7. HTTP POST DoS -- HTTP POST headers are sent to servers to let them know how much data is being sent, then the data is sent very slowly, eating up the servers' resources. When many of these are sent simultaneously, the servers are overwhelmed. (Created by Wong Onn Chee and Tom Brennan.)
8. JavaSnoop -- A Java agent attached to the target machine communicates with the JavaSnoop tool to test applications on the machine for security weaknesses. This could be a security tool or a hacking tool, depending on the user's mindset. (Created by Arshan Dabirsiagh.)
9. CSS History Hack in Firefox without JavaScript for Intranet Port Scanning -- Cascading style sheets, used to define the presentation of HTML, can be used to grab browser histories as victims visit Web sites. The history information can be used to set the victim up for phishing attacks. (Created by Robert "RSnake" Hansen.)
10. Java Applet DNS Rebinding -- A pair of Java applets direct a browser to a pair of attacker controlled Web sites, forcing the browser to bypass its DNS cache and so make it susceptible to an NDS rebinding attack. (Created by Stefano Di Paola.)
Read more about wide area network in Network World's Wide Area Network section.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Zeus botnet bank thieves were careless with own security
- Microsoft Subnet: An independent Microsoft community
- After attacks, Microsoft to rush out fix for ASP.net bug
- Quirky moments at Black Hat DC 2011
- netifera research - The ASP.NET Vulnerability - POET attack
- evercookie - virtually irrevocable persistent cookies
- Breaking Browsers: Hacking Auto-Complete (BlackHat USA 2010)
- Injection
- Attack and Defense Labs: Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution
- headers are sent
- Applications Research Center - Network World
- Aspect Security - JavaSnoop
- CSS History Hack In Firefox Without JavaScript for Intranet Portscanning ha.ckers.org web application security lab
- Wisec - The WIse SECurity
- LAN & WAN Research Center - Network World
- SOA and Business Processes: Making the Connection
- IDC Insight: V-Ray Gives Symantec NetBackup a Competitive Advantage Today and into the Future
- Top Reasons to Implement an SOA Governance Strategy: A List for IT Executives
- Transforming Software Delivery: An IBM Rational Case Study
- No Bull - What Customers Should Expect from Cloud Services
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Removing BPM Silos to Unleash Process Power - 15 Best Practices for Enterprise BPM
You are about to get a lot smarter about Enterprise Business Process Management (BPM ). T his article is the first in a series of our soon-to-be-published book, “The Intelligent Guide to Enterprise BPM .” So consider this first article your all-important primer. -
BPM Basics for Dummies
This book helps you understand what BPM is really all about. We wrote it because BPM is so useful and so powerful — and because it is also very accessible. We wrote this book for you — the individual. You may be a business manager, or an Information Technology practitioner, or maybe an ambitious career individual who wants to know what BPM is all about and how to apply it. -
How will CIOs meet growing Security Threats?
The growing complexity and prevalence of security threats, enabled by consumer IT and mobility, sets the stage for ever more sophisticated attacks. Security must be proactively front and center in all IT deliverables, but CIOs and CSOs must work in concert to succeed in these efforts. In this interactive white paper from CIO Magazine and EMC, learn how tightening the relationship between CIOs and CSOs will help create trust, the foundation of business relationships today. Embedded videos feature Art Coviello, Sanjay Mirchandani, and Dave Martin, and a quick survey provides benchmarking between CIO peers.
-
Teach Yourself Visually Windows 7
-
Office 2007 for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Seniors for Dummies®
-
Office 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Windows 7 for Dummies®








Comments
Post new comment