FREE Registration is required
Overview:
This paper describes a new attack against web authentication, which the paper calls dynamic pharming. Dynamic pharming works by hijacking DNS and sending the victim's browser malicious Javascript, which then exploits DNS rebinding vulnerabilities and the name-based same-origin policy to hijack a legitimate session after authentication has taken place. As a result, the attack works regardless of the authentication scheme used. Dynamic pharming enables the adversary to eavesdrop on sensitive content, forge transactions, sniff secondary passwords, etc. To counter dynamic pharming attacks, the paper proposes two locked same-origin policies for web browsers. In contrast to the legacy same-origin policy, which regulates cross-object access control in browsers using domain names, the locked same-origin policies enforce access using servers' X.509 certificates and public keys.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 424 KB | |
| Date: | Nov 2007 | ||
| Pages: | 14 |
People who downloaded this item also downloaded
White Papers, Webcasts, and Resources
- Create new value from System z assets, reduce costs with Web technology IBMFind out how you can integrate and enhance your System z assets faster when you use the version 6.1 update to IBM WebSphere Portal on...
- Sales 2.0: How Businesses are Using Online Collaboration to Spark Sales OracleExamine the rising use of LinkedIn, Facebook, Twitter, and other social media apps by sales and marketing teams to gain a competitive advantage.
- The Essential Guide: Real-Time High Availability for Exchange - Replicate Exchange Data for Improved Resiliency CA XOsoftSurvive major interruptions to your Exchange environment--and improve its resiliency and availability--with a real-time data replication solution.
Featured Training Courses
- Implementing and Administering Windows 7 in the Enterprise
- CCNA Boot Camp v2.0
- VMware vSphere: Install, Configure, Manage [V4]
- Certified Ethical Hacker
- Management and Leadership Skills
- Browse all Training Courses
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study



