Virtual Host Confusion: Weaknesses and Exploits

نویسندگان

  • Antoine Delignat-Lavaud
  • Karthikeyan Bhargavan
چکیده

Transport Layer Security (TLS) is commonly used to provide server-authenticated secure channels for HTTPS web applications. From the viewpoint of the client, however, the server authentication guarantees of HTTPS are frequently misconstrued to identify a single HTTPS endpoint or origin whereas, in practice, the HTTPS server may be serving any one of a large set of origins. This issue is even more acute in SPDY, a proposed successor to HTTP already in wide use today, because of a little-known feature that allows TLS sessions to be reused for requests to origins other than the one the session was negotiated for. We study current HTTPS server-side deployments and identify several vulnerabilities in server identification, all of which lead to serious attacks on popular websites and cloud-hosting infrastructures. We show that the common practice of using TLS certificates that cover multiple domains can be exploited if any one of the domains hosts untrusted content. We demonstrate that the use of shared TLS session caches and session tickets across different hosts and connection reuse in SPDY both weaken server authentication. By combining these vulnerabilities with widespread web server configuration problems, we describe practical, high-impact network-based redirection attacks that steal cookies and signon tokens, hijack sessions on popular websites, or can bypass certificate validation. To counter such attacks and to recover the isolation guarantees that are commonly assumed in shared hosting environments, we propose changes to web server software, TLS libraries, and the SPDY protocol and advocate prudent practices for the safe usage of TLS.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

RetroVisor: Nested Virtualization for Multi IaaS VM Availability

Nested virtualization [1] provides an extra layer of virtualization to enhance security with fairly reasonable performance impact. Usercentric vision of cloud computing gives a high-level of control on the whole infrastructure [2], such as untrusted dom0 [3, 4]. This paper introduces RetroVisor, a security architecture to seamlessly run a virtual machine (VM) on multiple hypervisors simultaneou...

متن کامل

Explaining the Views and Experiences of E-teacher and E-learners about Virtual Education in Yazd Shahid Sadoughi University of Medical Sciences

Introduction: Despite the fact that virtual education has been launched for a short time in medical sciences universities, especially Shahid Sadoughi University of Yazd, it is on initial steps. There is still no information available on the possible effects of this course so that we cannot identify the potential obstacles or problems or use its benefits in efficient way. In the present study, t...

متن کامل

Elementary school teachers' perception of educational and behavioral consequences of implementing evaluation in virtual space during the covid-19 pandemic: a phenomenological study

The purpose of the current research was to study the perception of primary school teachers about the educational and behavioral consequences of implementing evaluation in virtual space during the covid-19 pandemic. Therefore, the perception of elementary school teachers was investigated in a qualitative and phenomenological way. The research community included all the elementary school teachers...

متن کامل

VMSoar: a cognitive agent for network security

VMSoar is a cognitive network security agent designed for both network configuration and long-term security management. It performs automatic vulnerability assessments by exploring a configuration’s weaknesses and also performs network intrusion detection. VMSoar is built on the Soar cognitive architecture, and benefits from the general cognitive abilities of Soar, including learning from exper...

متن کامل

Analysis of In-service Virtual Training Courses from the Expert Staffs' Perspective of Vice Chancellor for treatment of Mashhad University of Medical Sciences (2013)

Background: In-service education is one of the best and major methods to provide, train and improve the performance of the staffs. This study aims to determine the strengths and weaknesses of the virtual trainings from the staffs' perspective of Mashhad University of medical sciences. Methods: this is a cross-sectional study conducted among staffs from different parts of the therapy department ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014