How Will Your Network Be Compromised? |
Written by Defending The Net Contributing Author: Darren W. Miller |
|||||
|
News Letter Article ID: 1544 |
||||||
Complex Hacking - Computer Compromise
Most of these vulnerabilities are very difficult to successfully exploit. Some of them require specific host platforms, special tools, in-depth knowledge of many programming languages, and a lot of luck. I'm not saying there are not tons of vulnerabilities and exploits like these, it's just that they are not always easy to take advantage of, and therefore, may not present themselves as high risk events for most organizations. It's The Little Things That Will Get You Every TimeDuring security assessments, there are times when I am able to successfully exploit a "technical" vulnerability to gain system or internal network access. For instance; during a recent assessment, I identified a web application server that appeared to be vulnerable to an IIS / ASP vulnerability that would allow an attacker to dump all .ASP code on the server. After some effort and a little C/C++ code, I was able to take advantage of this exploit. After perusing through the .ASP code on the server, I was able to gain important information that resulted in the comprise of an internal system. However, the reality is it is the simple things that are the biggest problem. Most times, internal network compromise is the result of one or more of the following:
The above is just a handful of "Little Things" that get overlooked and can result in the undoing of your networks security measures. As an example; Many organizations provide their internal and external customers with a public FTP service. Most times, this is done to allow people to easily post "non-critical" or public information and share it with other associates. Recently, I identified just such an FTP server. The server allowed anonymous logons, however it contained sub-directories that were secured. These secure directories were only accessible by the people who owned the account. It was obvious to me that I was not going to easily compromise these accounts. On the other hand, sitting right in the anonymous "root" directory was a .zip file that was rather large. I downloaded the file, which took quite a while, unzipped it on my desktop, and guess what it contained? It was a compressed file of the entire FTP server, including the secure directories. I would bore you with what I found within these directories. The bottom line is, I should have never had access to the information they contained. ConclusionThe bottom line is this; it really is the little things that will come back to haunt you when it comes to computer security. No system should ever be rushed into production. This is one of the most common causes for poorly secured systems. The team in charge of implementing new technology needs to be educated on how to securely deploy new systems. And if you are installing support software from outside vendors, make sure you thoroughly review their products security features. Also, make sure they fully disclose any known bugs or improperly functioning features. Return to the top of How Will Your Network Be Compromised page
|
Current News Letters
|
|||||
|
Computer Security Home | Press Releases | Online Survey | Site Index | Contact Us |
||||||
|
|