eWeek Security Watch
Advertisement
Advertisement
April 19, 2008 1:01 PM

Major ISPs Injecting Ads, Vulnerabilities into Entire Web



Dan Kaminsky goes Wild DNS security guru Dan Kaminsky says the practice by major ISPs to deploy advertising servers within trademarked domains (on error pages, for example) can expose the entire Web to malicious hacker attacks.

Kaminsky (left), a well-known researcher who helped with the Sony rootkit investigation, says the advertising servers are impersonating, via DNS, hostnames within trademarked domains. "We have determined that these injected servers are, in fact, vulnerable to cross-site scripting attacks. Since these servers are being injected into your trademarked domains, their vulnerability can be used to attack your users and your sites," Kaminsky said, identifying EarthLink, Verizon and Quest among the ISPs.

* Photo credit: Dave Bullock (Creative Commons 2.0)

Kaminsky demonstrated the flaw and discussed the security ramifications at the Toorcon Seattle conference this weekend.

During his talk, Kaminsky showed (.ppt file) how the vulnerable ad servers could be exploited for:

1. Arbitrary cookie retrieval. Any Web page on the Internet can retrieve all non-HTTP-only cookies from domains.

2. Fake site injection. A victim can be directed to "server2.www.realsite.com" or "server3.www.realsite.com," which will appear to be a host in a trademarked domain. We believe any phishing attempts from this perfect-address spoofed subdomain are more likely to be successful.

3. Full-page compromise. A victim can be directed to an actual HTTP site, with all logged-in credentials, and a hacker's attack page will still be able to fully manipulate the target site as if we ourselves were the victim. Note, while we cannot attack HTTPS resources, we can prevent upgrade from HTTP to HTTPS. This may affect any shopping carts within your sites.

In a statement sent to eWEEK's SecurityWatch ahead of his talk, Kaminsky said:

We believe this behavior is illustrative of the risks of violating Network Neutrality. Indeed, it is our sense that the HTTP web becomes insecurable if man-in-the-middle attacks are monetized by providers -- if we don't know what bits are going to reach the client, how can we control for flaws in those bits?

Kaminsky, who worked for penetration testing and consulting firm IOActive, said he was able to use a vulnerability in the search injection framework of Earthlink to partially compromise Microsoft's Live.com, eBay, the Associated Press, MySpace, Facebook and every other resource on the Web.

"Whereas Comcast outsources the operation of at least parts of their Washington network to EarthLink (who themselves are using equipment from a company called BareFruit), this is potentially affecting millions of users," he added.

Threat Level's Ryan Singel reported that the BareFruit vulnerability was quietly patched on April 18, 2008, a day before Kaminsky's talk. More from Brian Krebs at SecurityFix.

Create, Communicate, Collaborate with IT Professionals at Ziff Davis Enterprise IT Link

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/13344

Comments (5)

Charles Hixson :

So I tried to contact Earthlink to ask them about this. Unfortunately, there appears to be no way to contact anyone who could speak to this issue. I'm having serious reservations about my account with them.

Joe S. :

I have an account with Verizon. I'm going to ask them why I should continue to do business with someone who leaves me open to attack. Maybe they think they're so big we can't find other providers, or maybe they just count on us to be too lazy.

Barry Williams :

I will, like most of the few knowledgeable web users, "vote with my feet" to the extent that it is possible.

In the final analysis, maybe governments and web-governance need to put a stop to the practice.

Nick Woodson :

Now we've got a 'vote the bums out' problem. It seems that the current congress (or political structure in general) has no inclination to regulate anything....so to hell with you and your piddling problems!

All we can hope is that some form of technical competence in government can pevail....that or that a major government system gets compromised so that the pain becomes "real".

Nick Woodson :

Now we've got a 'vote the bums out' problem. It seems that the current congress (or political structure in general) has no inclination to regulate anything....so to hell with you and your piddling problems!

All we can hope is that some form of technical competence in government can pevail....that or that a major government system gets compromised so that the pain becomes "real".

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise