Network World
Friday, January 9, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Yeah, it's bad

0

Agreed, it's real bad. Hence the title of our talk. I think we're doing the best we can with a tough situation. I think Sun is going to have a patch available shortly after Black Hat that will give us a temporary fix, but there will just be another vector like this somewhere down the road.

Billy and I talked about taking ownership of content, or as we like to call it taking pwnership of content, last year at DEFCON. Back then, we were uploading Flash cross domain policy files in this fashion. We still have some simple attacks like that. One of the flaws we'll demo in our talk is a straight up upload of a java applet to the site. Forget GIFARs.

People need to understand the dangers of accepting user uploaded data and hosting it from the same domain as the application itself. The GIFAR stuff is interesting, but the end result is that even with that gone, this is still an issue in some cases.

-Nate

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: