Digital signatures are not a new concept in the security world. The process is fairly simple: take some data, apply a hash algorithm to it, encrypt the hash with a private key, and then store the resulting signature somewhere. Assuming you don’t have to implement the cryptographic algorithms (which you shouldn’t), the process is very easy. So, why is it so hard to do over the web? For one thing, most security libraries have made the problem too easy to tackle. Libraries such as CAPI for Windows, BouncyCastle for Java, and OpenSSL for C like to make creating digital signatures a one-function event. Pass in the data, certificate, key, and you get your PKCS7 signature block. This works great for[…]
Category: software
Fraudsters have taken advantage of a weakness in PayPal’s application to insert some XSS which ends up feeding your credit card number to their site. Surprisingly, it was first caught with Netcraft’s anti-phishing toolbar rather than some security experts. The full story is on Netcraft’s site.
As read in eWeek, Vista Beta 2 includes Address Space Layout Randomization, or ASLR. [Michael Howard, Sr. Security Program Manager at Microsoft] said the job of ASLR is to move function entry points around in memory so they are in unpredictable locations. In the case of Windows Vista Beta 2, a DLL or EXE could be loaded into any of 256 locations, which means an attacker has a one-in-256 chance of getting the address right. It’s a little something which might thwart malware attempting to exploit buffer overflows. It will probably help. I hope it doesn’t introduce some sort of bug though. Imagine if one out of every 256 times your program crashed unexpectedly. Then again, how different is that[…]
Here’s an example of why security adoption can be so slow and fraught with difficulty. My brother, an IIS and Exchange administrator for a large corporation, ran into an interesting problem. He was moving their Outlook Web Access installation from a single web server to a load-balanced cluster of three servers. He changed the DNS entry to point to the new cluster, and began to see unexplained errors in client web browsers. Internet Explorer (on some machines) was complaining of an expired certificate, but the whole certificate path displayed by IE was current and valid. Firefox was complaining with a “Website Certified by an Unknown Authority” error. All very confusing. Problem was solved with some clever googling. The problem was[…]
You may want to hold back that itchy double-click finger when it comes to opening word attachments in emails, at least till Microsoft gets a new patch out. A zero-day flaw in the ubiquitous Microsoft Word software program is being used in an active exploit by sophisticated hackers in China and Taiwan, according to warnings from anti-virus researchers. … The exploit arrives as an ordinary Microsoft Word document attachment to an e-mail. However, when the document is launched by the user the vulnerability is triggered to drop a backdoor with rootkit features to mask itself from anti-virus scanners. Full article from eWeek via /.
Gary McGraw, CTO of Cigital Inc., has written this article with some insight on why Vista isn’t written using .NET. The problem, it turns out, is that the .NET builders did not give much thought to providing many of the essential basic building blocks that operating systems construction crews need for their work. Interpreted code has some minor performance issues as well (note that there are many ways to overcome this often overly shrill critique). But the main problem was that the Microsoft OS guys are big C++ users. Interpreted languages such as .NET and Java before it provide some great advantages when it comes to writing secure less hackable operating systems: type safety: making sure that an integer is[…]