Home > Ask the Security Experts > Information Security Threats Questions & Answers > What are the basics of a Web browser exploit?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are the basics of a Web browser exploit?

John Strand EXPERT RESPONSE FROM: John Strand

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 August 2008
Can you explain the basics of a Web browser exploit, and can you provide an example of how one can enable an attacker to infect an enterprise system?

>
EXPERT RESPONSE
Let's first look at a class of threats where the attacker targets a vulnerability in either the browser or in an application that the browser calls to process a Web request. For example, an attacker could use the mozilla_compareto module -- a Metasploit module that builds on the research of Aviv Raff -- to have their system act as a Web server. When an unsuspecting victim connects to the evil attacker's site, it launches an attack against the browser itself, creating a shell on the target system for the malicious hacker.

An attacker can also target an application that the browser uses to properly render a website. For example, an attacker can attack RealPlayer, QuickTime, or even the victim's antivirus program.

Next, an attacker can submit a malicious Javascript request to the browser, a technique also known as cross-site scripting (XSS) or cross-site request forgery (XSRF). In addition to XSS and XSRF, a creative attacker can gain access to a victim's browsing history, or what is currently in the victim's clipboard. The contents can include the user's password or credit card numbers. The tool that best articulates these attacks is the Browser Exploitation Framework by Wade Alcorn at bindshell.net.

Defense against these types of threats should always focus on educating users not to click on links from strangers and to be wary of certificate errors. Security managers should spend some time considering which websites users need to go to do their jobs. Also consider developing a white-list approach to user Web access. The filtering would permit users to only access websites that are approved, while blocking everything else.

More information:

  • Researchers at this year's Black Hat 2008 conference revealed how to use the browser to elude Vista memory protections.
  • Get the latest browser security news and expert advice.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Information Security Threats
    Are daily antivirus scans in XP Normal Mode effective if malware must be removed in Safe Mode?
    What is the best way to manually test for buffer overflows?
    Can virtualized applications interact with each other without explicit permission?
    What is the best way to conduct a rootkit-specific risk assessment?
    Does the iPhone SDK effectively increase the risk iPhones pose?
    How can widget malware on social networking sites threaten enterprises?
    Will the new CERT security incident-response project benefit infosec pros?
    How can an enterprise-wide network remain resilient against denial-of-service (DoS) attacks?
    Can "good" botnets fight bad botnets?
    Are there antivirus suites that pick up more than just run-of-the-mill viruses?

    Application Attacks (Buffer Overflows, Cross-Site Scripting)
    Microsoft Windows XML flaw exploits test desktop antimalware
    How to prevent clickjacking attacks with security policy, not technology
    Mozilla fixes cross-site-scripting flaws
    Microsoft updates code analysis tool, SQL injection XSS library
    Cisco: Cybercriminals more savvy than ever in 2008
    Flash, PDF are growing malware targets
    Holiday shopping threats
    Spam declines, Web-based attacks rise, says MessageLabs
    Web app attacks grow, but developers may fight back
    What risks do application virtualization products pose to enterprise security?
    Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

    Web Application Security (Also see Web Access Control)
    Dangerous Java flaws could expose sensitive data
    Cloud compliance: How to manage SaaS risk
    Symantec to acquire MessageLabs for SaaS model
    Clickjacking details released after attack proof-of-concept emerges
    Billy Hoffman on AJAX security and browser attacks
    Data risks take shine off Google Chrome
    Verizon breach study identifies industry specific threats
    IronPort feature detects exploited websites
    PCI DSS 1.2 clarifies wireless, antivirus use
    MySpace, Facebook ignoring basic principles of security

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    cache poisoning  (SearchSecurity.com)
    cyberterrorism  (SearchSecurity.com)
    dictionary attack  (SearchSecurity.com)
    directory harvest attack  (SearchSecurity.com)
    distributed denial-of-service attack  (SearchSecurity.com)
    JavaScript hijacking  (SearchSecurity.com)
    ping of death  (SearchSecurity.com)
    script kiddy  (SearchSecurity.com)
    stack smashing  (SearchSecurity.com)
    SYN flooding  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts