Here is
an advisory from the KDE project
regarding a flaw in Konqueror's digital certificate handling. It seems
that Konqueror (along with certain other, proprietary web browsers) doesn't
look hard enough at how a site's certificate was signed, meaning that
anybody can fake a certificate for anybody else's site. Thus, with a
little additional trickery, it would be possible to set up "man in the
middle" attacks and steal credit card numbers.
The Register described this
vulnerability as "a colossal stuff-up." Certainly the error is worth
fixing, but anybody who is greatly concerned about this vulnerability would
be well advised to look at the end of the "Certificates and Credentials"
chapter in Bruce Schneier's Secrets & Lies:
I visited www.palm.com to purchase something for my PalmPilot.
When I went to the online checkout, I was redirected to
https://palmorder.modusmedia.com/asp/store.asp. The SSL
certificate was registered to Modus Media Internatinoal; clearly a
flagrant attempt to defraud web customers, which I deftly uncovered
because I carefully checked the SSL certificate. Not.
All that SSL does in almost every use is to verify that the remote site has
a certificate issued by a trusted authority. There is no verification that
said certificate has anything to do with the site that the user expects to
be interacting with. Man in the middle attacks are easily done even when
the web browser properly checks how digital certificates were signed; the
Konqueror vulnerability has not really opened up any new holes.
The real issue, which nobody is all that concerned about, is that the
digital certificate system is not doing much for its users. Quoting
Schneier again: "Digital certificates provide no actual security for
electronic commerce; it's a complete sham.
" Konqueror users should
go ahead and apply the patch (see the LWN
vulnerability entry for distributor updates as they arrive), but it's
not going to make them all that much more secure against man in the middle
attacks.
Comments (1 posted)
Bruce Schneier's CRYPTO-GRAM newsletter for August is out; it includes a
look at Palladium, the proposed law allowing attacks against online
copyright violators, and the idea of arming airline pilots. "
To me,
it's another example of the insane lengths the entertainment companies are
willing to go to preserve their business models. They're willing to
destroy your privacy, have general-purpose computers declared illegal, and
exercise special vigilante police powers that no one else has...just to
make sure that no one watches 'The Little Mermaid' without paying for it.
They're trying to invent a new crime: interference with a business
model.
"
Full Story (comments: none)
FUDforum is a web-based forum
system. Ulf Harnhammar has reported two vulnerabilities in this package;
one can provide access to files outside of the FUDforum directory, and the
other can lead to SQL injection issues. The problems have been fixed in
version 2.2.0.
Full Story (comments: none)
A new cross-site scripting vulnerability has been reported in PHP-Nuke
v5.6; properly exploited, this hole can be used to obtain access to the
site's administrative accounts. No fix is available as of this writing.
(Additional note: this vulnerability was actually
first
reported in March. PostNuke also, apparently, has this problem).
Full Story (comments: none)
php-affiliate - a script for running web site affiliate programs - places a
little too much trust in the hidden fields it puts into forms, with the
result that users can modify information belonging to other users.
Full Story (comments: none)
The
Web Shop
Manager e-commerce system has trivial remote command execution
vulnerability. This problem exists in version 1.1; no updates are yet
visible on the project web site.
Full Story (comments: none)
The folks at SecurityFocus have set up two new mailing lists for security
discussions - one aimed at BSD systems, and the "unix-other" list for
proprietary Unix systems.
Full Story (comments: none)
The LinuxSecurity.com weekly newsletter for August 19 is available.
Full Story (comments: none)