As the world sits back and waits for Coronavirus to pass, the normally frantic pace of security news has slowed just a bit. Google is not exempt, and Chrome 81 has been delayed as a result. Major updates to Chrome and Chrome OS are paused indefinitely, but security updates will continue as normal. In fact, Google has verified that the security related updates will be packaged as minor updates to Chrome 80.
Speaking of COVID-19, researchers at Check Point Research stumbled upon a malware campaign that takes advantage of the current health scare. A pair of malicious RTF documents were being sent to various Mongolian targets. Created with a tool called Royal Road, these files target a set of older Microsoft Word vulnerabilities.
This particular attack drops its payload in the Microsoft Word startup folder, waiting for the next time Word is launched to run the next stage. This is a clever strategy, as it would temporarily deflect attention from the malicious files. The final payload is a custom RAT (Remote Access Trojan) that can take screenshots, upload and download files, etc.
While the standard disclaimer about the difficulty of attribution does apply, this particular attack seems to be originating from Chinese intelligence agencies. While the Coronavirus angle is new, this campaign seems to stretch back to 2017.
Its a fairly common practice to build web services with a dedicated front-end server, and then a back-end server or group of servers. I just recently migrated a handful of websites that I host to this paradigm, using an Nginx server as a shared front-end that routes traffic to the appropriate Apache back-end server. Nginx scales better than Apache, and it helps ration public IPv4 addresses. There is an attack that takes advantage of this arrangement: HTTP request smuggling.
When using a dedicated front-end, common practice is to share a TCP connection, and potentially an SSL connection, and send all the traffic to the back-end in a single shared stream. Particularly when using SSL, the performance gain is substantial. Using a shared stream does introduce a dose of extra complexity. What happens when the front-end interprets a request differently than the back-end, and how does the back-end make sure to keep requests separate?
Back in 2005, an attack was devised that took advantage of the problems inherent in these two questions. The original HTTP Request Smuggling attack (whitepaper) was as simple as including two Content-Length headers in a request. It was found that in some combinations of front-end and back-end software, the front-end would use the last Content-Length header to interpret the request, whereas the web server itself would use the first header. With a bit of careful request crafting, then, an attacker could send a single HTTP request to the front-end, and have that single request interpreted as two separate requests by the back-end. This seems like a rather unimpressive attack, until you consider that many deployments rely on the front-end server for request verification and security controls. If you can sneak a malicious request past the front-end by embedding it in one that is harmless, you may have a path to attack the back-end server directly.
Request Smuggling didnt catch on as a viable attack, and so much time has passed that all the major products automatically catch and mitigate this particular attack. Revealed at DEF CON 27, HTTP Desync is a new take on this old attack. Rather than specify content-length twice, this attack uses both content-length and chunked encoding. Its another approach to the same end goal, give two different lengths that are understood differently. There are a handful of clever techniques that [James Kettle] covered in his DEF CON talk, like adding non-standard white spaces in the Transfer-Encoding: chunked header. One end sees the header as non-standard and ignores it, and the other might clean up the whitespace before processing the headers, leading to desync.
You may think that SSL protects against this technique, but were describing a scenario where the SSL certificate is installed on the front-end server. All the incoming requests are decrypted and interleaved together, and then may or may not get re-encrypted en route to the back-end. Because its that interleaving that gives rise to this class of vulnerability, the SSL connection doesnt have an impact.
What can you actually do with this sort of attack? Bypass source IP restrictions to a certain endpoint, to name the simplest. Have your WordPress sites /wp-admin page restricted to just one IP address? An HTTP Desync can bypass that restriction. In another example, [James] was able to dump all the custom HTTP headers the front-end was using, and then spoof some of those headers to gain admin access to an entire web service. The whole talk is great, check it out below:
The related news from this week, [Emile Fugulin] took a look at HTTP Desyncs and discovered that Amazons Application Load Balancer is potentially vulnerable in its default configuration, when paired with a Gunicorn back-end. If youre using ALB, he suggests looking at the routing.http.drop_invalid_header_fields.enabled option, and turning it on if you can. Gunicorn has been patched, so go make sure youre running the latest version there, as well.
Well this is awkward. Trend Micro disclosed a set of five security bugs in its products, and revealed that two of them have been actively exploited by attackers. The details are a bit sparse, but it seems that the two attacks found in the wild require some level of authentication before they could be exploited. The two vulnerabilities that seem the most alarming are CVE-2020-8598 and CVE-2020-8599, both of which allow remote compromise before any authentication. Its humorous to see that the vulnerability bulletin lists a mitigating factor, paraphrased: You have a firewall and NAT, right? If you use Trend Micro, make sure its up to date, and maybe do a quick audit on what ports are open on your workstations.
This story sneaked in just in time. An unnamed security researcher discovered a flaw in Netflixs handling of session cookies, combined with their use of unsecured HTTP connections for a few endpoints. Yes, Netflix is still vulnerable to Firesheep.
That could have been the end of the story Netflix should have made their bug bounty payment, fixed their unsecured subdomain, and all would be well. Instead, when our anonymous researcher submitted his finding through Bugcrowd, the firm that handles Netflixs bug bounty program, the official response was that this finding is out-of-scope for a reward. Thats not surprising, its normal for a researcher to disagree with the target company about how important a vulnerability is. As one might expect, once the researcher was told his findings were out-of-scope, he made them public and shortly got an official scolding from Bugcrowd. Apparently an out-of-scope bug submission is still in-scope enough to be kept secret. Even more concerning, Bugcrowds documentation doesnt seem to include a set timeline, but implies that all disclosure must first receive the target companys permission.
Bug-bounties are great, but Bugcrowd puts researchers into an ugly catch-22. I think its ethically rotten to refuse a payout, and then continue to hold a researcher over the barrel on an issue.
Thats it for this week, stay safe and do some security research!
Read the original post:
This Week In Security: Working From Home Edition - Hackaday
- The Best MyQ Home Security Devices To Help Give You Peace Of Mind - Forbes - March 17th, 2025 [March 17th, 2025]
- How Home Alarm System Brand ADT Learned To Love CTV - AdExchanger - March 17th, 2025 [March 17th, 2025]
- Teyana Taylor Will Receive 4 Homes Worth More Than $10 Million as Part of Multimillion-Dollar Divorce Settlement With Iman Shumpert - SFGATE - March 17th, 2025 [March 17th, 2025]
- This solar-powered outdoor camera might be the only one you'll ever need - ZDNet - March 17th, 2025 [March 17th, 2025]
- Is There a Security Camera That Works Without Wi-Fi? - Security.org - March 17th, 2025 [March 17th, 2025]
- Lily Allen and David Harbour Turned Their Brooklyn Home Into 'Weird' Floral WonderlandSo, What Becomes of It Amid Rumored Split? - SFGATE - February 8th, 2025 [February 8th, 2025]
- Caught on camera: Bixby woman nearly walks in on masked burglar in her home - news9.com KWTV - February 8th, 2025 [February 8th, 2025]
- Smart Lock Market to Attain Valuation of US$ 15.42 Billion by 2032 - Yahoo Finance - February 8th, 2025 [February 8th, 2025]
- Travis Kelce goes full John Wick on home security after burglary - Marca English - February 8th, 2025 [February 8th, 2025]
- Google Nest Security Camera With Floodlight Wont Stay This Cheap for Long, First Price Drop in Months - Gizmodo - February 8th, 2025 [February 8th, 2025]
- The 3 Best Smart Water-Leak Detectors of 2025 | Reviews by Wirecutter - Wirecutter, A New York Times Company - February 8th, 2025 [February 8th, 2025]
- Oil Billionaire Bill Koch Lists His Eco-Friendly 'Once in a Lifetime' Aspen Estate for $125 MillionMore Than Four Times What He Paid - SFGATE - February 8th, 2025 [February 8th, 2025]
- Home Security Systems Market is anticipated to project robust - openPR - February 8th, 2025 [February 8th, 2025]
- The best Wyze Cam alternative I've tested is only $20 with this deal - ZDNet - February 8th, 2025 [February 8th, 2025]
- Eufy SoloCam S340 review: a solar-powered and fully wireless outdoor security camera - The Independent - February 8th, 2025 [February 8th, 2025]
- Smart Lock Buying Guide: Picking Locks the Right Way - CNET - February 8th, 2025 [February 8th, 2025]
- Trump's Homeland Security pick pressed on domestic terrorism in hearing - NPR - January 21st, 2025 [January 21st, 2025]
- Man watches in horror from security camera as California wildfire engulfs his home: 'All I could do' - Fox Weather - January 21st, 2025 [January 21st, 2025]
- Unprecedented video shows falling meteorite, records sound of impact - For The Win - January 21st, 2025 [January 21st, 2025]
- HomeKit Weekly: Combat dry winter air with the SwitchBot Smart Evaporative Humidifier - 9to5Mac - January 21st, 2025 [January 21st, 2025]
- The Google Home app is getting a big update, and it's good news for your security - TechRadar - January 21st, 2025 [January 21st, 2025]
- 6 ways Reolink's CES 2025 gadgets upped the ante for every other security camera this year - Android Police - January 21st, 2025 [January 21st, 2025]
- No Monthly Fee, the Eufy Security Floodlight Cam Is Now More Affordable Than Ever - Gizmodo - January 21st, 2025 [January 21st, 2025]
- Sound of Meteorite Hitting Earth Recorded by Security Camera Moments After Couple Left Home to Walk Their Dogs - PEOPLE - January 21st, 2025 [January 21st, 2025]
- Attempted burglary in Cranford highlights importance of home security - News 12 New Jersey - January 3rd, 2025 [January 3rd, 2025]
- Matthew Stafford had police inspect his home for potential security flaws amid burglaries - Rams Wire - January 3rd, 2025 [January 3rd, 2025]
- The Ring Stick Up Cam Pro drops to its all-time low price! - Android Authority - January 3rd, 2025 [January 3rd, 2025]
- Dallas Mavericks star Luka Doncic's home targeted in string of home burglaries - CBS News - January 3rd, 2025 [January 3rd, 2025]
- How Wireless Doorbell Kits Are Changing Home Security for the Better - openPR - January 3rd, 2025 [January 3rd, 2025]
- What UHNWs can learn about home security from 10 million London mansion heist - Spear's WMS - January 3rd, 2025 [January 3rd, 2025]
- Luxury Turns to Loss: Shafira Huangs Shocking Theft - Qhubo - January 3rd, 2025 [January 3rd, 2025]
- Home Tech Companies Are Peddling 'Affectionate Intelligence.' Should We Fall for It? - CNET - January 3rd, 2025 [January 3rd, 2025]
- The Best of Smart Home in 2024: The 10 Articles You Read the Most - How-To Geek - January 3rd, 2025 [January 3rd, 2025]
- The Top Home Security Mistakes to Stop Making in 2025 - CNET - January 3rd, 2025 [January 3rd, 2025]
- MagSafe Monday: LISEN delivers the strongest MagSafe magnet Ive found for the car - 9to5Mac - January 3rd, 2025 [January 3rd, 2025]
- The best floodlight and security camera combo I've tested is $70 off - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- I invested in a subscription-less video doorbell, and it's paying off for my smart home - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- NBA follows NFL in warning players on burglaries - ESPN - November 29th, 2024 [November 29th, 2024]
- Find heavily discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- This Floodlight Camera Has My Backyard Covered, and It's Under $100 for Black Friday - Lifehacker - November 29th, 2024 [November 29th, 2024]
- Get the ultimate home security this holiday season with Wyze starting at $17 - New York Post - November 29th, 2024 [November 29th, 2024]
- This Is the Best Black Friday Deal for an All-Purpose Security Cam I've Ever Seen - CNET - November 29th, 2024 [November 29th, 2024]
- NBA memo to players urges increased vigilance regarding home security following break-ins - Ashland Daily Press - November 29th, 2024 [November 29th, 2024]
- Find discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- The 4 Most Common Package Scams in 2024 -- and How to Stop Them - CNET - November 29th, 2024 [November 29th, 2024]
- Keep Your Home Protected During Your Holiday Travel With Up to 60% Off Blink Outdoor 4 Cams - CNET - November 21st, 2024 [November 21st, 2024]
- Editor's Note: Whats Old is New and Innovative Again? - SecurityInfoWatch - November 21st, 2024 [November 21st, 2024]
- Beef Up Your Home Security and Get Up to 77% Off With These Arlo Black Friday Deals - CNET - November 21st, 2024 [November 21st, 2024]
- Ive ditched my Nest Cams for a Chinese smart security brand you probably havent heard of - The Ambient - November 21st, 2024 [November 21st, 2024]
- Boost Your Home's Security With the Outdoor Roku Cam, Down to $20 for Black Friday - CNET - November 21st, 2024 [November 21st, 2024]
- Home Security Experts Share Important Insights About the Travis Kelce and Patrick Mahomes Burglaries - House Beautiful - November 21st, 2024 [November 21st, 2024]
- Infinity Symbol-Shaped Circular House Hits the Market for the Unique Price of $3,399,888 - SFGATE - November 21st, 2024 [November 21st, 2024]
- The Blink Outdoor 4 Home Security Cameras Are Cheaper Than Last Year's Black Friday Prices - Gizmodo - November 21st, 2024 [November 21st, 2024]
- Blink Mini 2 review: this home security camera is good price, but unimpressive performance might make you think twice - TechRadar - November 21st, 2024 [November 21st, 2024]
- How to Scrub Your Home Address Off the Internet and Keep It Off - CNET - November 21st, 2024 [November 21st, 2024]
- Defiant Smart Home Alarm Kit review: Just the basics - TechHive - November 21st, 2024 [November 21st, 2024]
- New Report Cites Six Outdoor Home Improvements That Enhance Wellness - Forbes - November 21st, 2024 [November 21st, 2024]
- 3 New AI Smart Home Features Arrive With Gemini and Google Nest - CNET - November 21st, 2024 [November 21st, 2024]
- Announcing the 2024 Readers' Choice Product Awards! - SecurityInfoWatch - November 21st, 2024 [November 21st, 2024]
- The Arlo 2K battery-powered security camera is 60% off before Black Friday - ZDNet - November 21st, 2024 [November 21st, 2024]
- Abilene Police expert offers advice on safeguarding your home during the holiday season - KTXS - November 21st, 2024 [November 21st, 2024]
- Travis Kelce and Taylor Swift take drastic measures after home burglary: 'They have 24-hour armed security staff' - Marca.com - November 21st, 2024 [November 21st, 2024]
- Smart Home Security Market will increase to USD 10.25 Billion by 2030 - openPR - November 21st, 2024 [November 21st, 2024]
- Want better home security? Dont miss these Reolink early Black Friday deals - Digital Trends - November 21st, 2024 [November 21st, 2024]
- An Interview With the Target & Home Depot Hacker - Krebs on Security - November 21st, 2024 [November 21st, 2024]
- Protect Your Home Title & Equity from Fraud with TripleLock Monitoring, Alerts & Restoration - ABC Action News Tampa Bay - November 12th, 2024 [November 12th, 2024]
- Wireless Home Security Camera Market is growing at a CAGR of 20% in the forecast period (2024-2031) - openPR - November 12th, 2024 [November 12th, 2024]
- Yes, Smart Homes Are Vulnerable to Cybercriminals. Here's What You Need to Know. - House Beautiful - November 12th, 2024 [November 12th, 2024]
- Limited-Time Deal: Protect Your Home or Business With a Ring Indoor Camera at Almost 40% Off - CNET - November 12th, 2024 [November 12th, 2024]
- The 3 Best Indoor Security Cameras of 2024 | Reviews by Wirecutter - Wirecutter, A New York Times Company - November 12th, 2024 [November 12th, 2024]
- Get home security cameras up to 60% off and feel extra cozy this winter - Mashable - November 12th, 2024 [November 12th, 2024]
- Resideo Unveils Honeywell Home FocusPRO Thermostats - SecurityInformed - November 12th, 2024 [November 12th, 2024]
- A Smart Before-the-Holidays Decision: Arlo and Allstate are Boosting Peace of Mind with New Home Security Bundle - IoT Evolution World - November 12th, 2024 [November 12th, 2024]
- The Google Nest Cam With Floodlight Is at Its Lowest Ever Price, but Not for Long - CNET - November 12th, 2024 [November 12th, 2024]
- Man shot by security guard at Home Depot in Northeast Philly - The Philadelphia Inquirer - November 12th, 2024 [November 12th, 2024]
- Keep Eyes on Your Home at All Times With a Blink Outdoor Cam for 60% Off - CNET - November 12th, 2024 [November 12th, 2024]
- A Letter to the Nation's New Leaders: Right Now, the American Dream of Homeownership Is in Crisis - SFGATE - November 12th, 2024 [November 12th, 2024]
- Get your tickets SECURED to Z100s Jingle Ball from Slomins Home Security! - iHeart - November 12th, 2024 [November 12th, 2024]
- We test a new home security package that couldn't be simpler to install - The Scotsman - November 12th, 2024 [November 12th, 2024]
- 6 Smart Gadgets That Will Instantly Upgrade Any Home's Lighting And Security - SlashGear - November 12th, 2024 [November 12th, 2024]