November 20, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Security Syndicate This
Print this article    Email this article    Talk Back!    Write to Editor
CSRF Attack: Not Only Nasty, But Hard to Detect
08/04/2008
By Mike Rothman, President and Principal Analyst, Security Incite
Untitled Document Editor's Note: Want to learn about security architectures for SOA? Attend this Wednesday's upcoming ebizQ webinar right here.

As we've done in recent months (here and here), we are going to dive into a fairly common attack and understand how it happens and most importantly what you can do to stop it. The attack du jour is called Cross-site Request Forgery (CSRF) and it may be the most sophisticated attack out there -- and also the hardest to detect and defend against.

ADVERTISEMENT
Our Popular Webinars
Insurance: Discovering the Missing Link of Business Architecture
SOA Infrastructure for any economic climate
Adapt with Agility - Web 2.0 in your Application Infrastructure
Open Source SOA and the Management Challenge: The ROI and Reliability of Open Source Composite Applications
Guaranteeing Agility in SOA and BPM with Process-Driven Data Integration
More Webinars

A key similarity that CSRF has with cross-site scripting is the attack targets the user, not necessarily your web site. So you could, in effect, be the carrier for this attack, compromising both your visitors, as well as other high profile sites.


Stuck with an outdated security model that's holding you back from the big benefits of connectivity? Learn how to reap the rewards of fast, reliable, and inexpensive connectivity right here.

What is CSRF? How does it happen?

CSRF is a pretty ingenious attack. Basically, the attacker embeds malicious code onto a web site (via images, HTML or JavaScript), and when the user renders the page (and presumably executes the malicious code), a request on behalf of the user (inheriting his/her identity and privileges) is sent to a third site, but unbeknownst to the user. The third site has no idea the request is not legitimate (since it comes from a verified identity with a legitimate credential), so it honors the request -- which is usually bad for the user.

In the example of the highest profile CSRF attack to date, Gmail was targeted. The attack basically was embedded into many web sites, which then would request that Gmail add a filter to forward a copy of all mail to the attacker's email address. Yes, the user had no idea that they actually authorized Google to send all their mail to the attacker.

The only way folks realized this was to peruse their list of filters and look for something suspicious. If you have a ton of filters, like I do, that's kind of hard -- so it's not surprising that some of the best security folks I know got nailed from this attack.

Page 1

More Top Stories
Identity Networking: Where Security and Compliance Meet Gold Club Protected
Get Smart About Database Security Gold Club Protected
Business and IT Alignment: A Road to Nowhere? Gold Club Protected
BI in Healthcare: Have Providers Found a Cure? Gold Club Protected
Maximizing User Experience and Perfomance Gold Club Protected
Property & Casualty Markets - Riding the Waves or Flattening the Curve Gold Club Protected
More Top Stories
Related News
Mosso, Rackspace's Cloud Division, Enables Cloud Files with Limelight Networks Content Delivery Service
Paradigm Posts Scientific Challenge to InnoCentive's Open Innovation Approach Seeks New Advanced Method for 3D Fracture Net Representation
NICHD Deploying Lombardi BPM Suite
More News
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
Create a Center of Excellence in SOA Governance
Date: Dec 02, 2008
Time: 12:00 PM ET
(17:00 GMT)

REGISTER TODAY!
Next-Generation BI
Date: Dec 03, 2008
Time: 12:00 PM ET
(17:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  Extending the business value of SOA through BPM
According to leading analyst firms, SOA and BPM are mutually beneficial initiatives. According to many CIO polls, organizations often approach SOA...Learn More
ebizQ also recommends
 Formalizing Operational Governance: Ensuring the well-managed enterprise
 15-Minute Guide to Transactional Content Management
 EMC Forges Ahead In Document-Centric BPMS, The Forrester Wave Vendor Summary
 The Forrester Wave: Business Process Management for Document Processes
 From Vision to Reality: Bridging The HR And Benefits Universe With The Employee Communications Platform
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map

Live Chat