Hacker
Hackers could manipulate the http: verb to bypass otherwise effective security controls
R E L A T E D   C O N T E N T
ADVERTISEMENT

Bug exposed in web security standard

VBAAC flaw could affect hundreds of thousands of sites

Robert Jaques, vnunet.com 10 Jun 2008
ADVERTISEMENT

Security experts have warned of a critical bug in the standard web authorisation technology used by hundreds of thousands of websites.

Fortify Software has identified a problem with the VBAAC (Verb-based access and authentication control) aspect of web security technology which affects a number of different products.

The flaw allows hackers to manipulate the http: verb to bypass otherwise effective security controls.

Rob Rachwald, director of product marketing at Fortify, said: "The flaw is unusual in being systemic and therefore not directed at any one vendor's products."

The flaw is essentially "a bug in a security feature", according to Rachwald, and the most popular J2EE container applications all have the flaw inherent in their authorisation procedures.

"For example, a piece of http: code might seek to limit access to a given directory except for those users logged in with Admin rights," he said.

"Exploiting the flaw means that, instead of blocking approaches not specified in a security rule, the code allows almost any method that is not specified.

"Using this approach leaves the system open to infection by malware, or perhaps worse. By listing specific methods in the security rule, software developers end up opening the system a lot wider than they originally intended. "

The flaw can be prevented by programming the web and application server system to disallow non-standard requests such as 'Head', as well as never serving the JSPs directly but placing all JSP-INF files into a container (e.g. Web-Inf) and limiting calls to that container.

"Direct calls to JSPs should be avoided if at all possible. Developers should always invoke the request from the environment they are expected to be in and not from a dictionary collection of request data," said Rachwald.

See also:

HackerUK second most dangerous country after Italy  09 Jun 2008
HackerSQL injection attacks colonising big name sites  09 Jun 2008
Data breachOverwhelming majority would want to know if their details were lost or stolen  06 Jun 2008
HackerGive us your money or the data gets it  06 Jun 2008

All Bugs & Fixes
Tags: Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Background A fantastic opportunity has just arisen within this growing multinational organisation. Working as an EMEA Advisory Consultant your main duties and responsibilities will be to provide advice and support to international organisations looking to ... more >
| Aston Carter
This is a hands-on development team lead position that will push you to the limit of your architectural and mentoring capabilities. Technical amp; development (Agile) • Create effective data solutions, in partnership with the relevant ... more >
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Computer People
Junior Network Operations Engineer – Borehamwood - £24k Junior / entry level network operations engineer required, will be responsible for supporting external clients network and security solutions. Excellent entry level position as my client offers ... more >
More job opportunities