Latest news
To discuss this vulnerability and its implications we talked with Amichai Shulman, the co-founder and CTO of Imperva, where he heads the ADC. Under his direction, the ADC has been credited with the discovery of serious vulnerabilities in commercial Web application and database products, including Oracle, IBM, and Microsoft.
In your opinion, what is going to be the impact of this vulnerability?
This is very alarming for any application using DWR. It requires application programmers to take immediate actions as a workaround. I think DWR writers will have to issue a patched version soon.
Are you expecting more such vulnerabilities in the near future?
I certainly do. Most people think of AJAX vulnerabilities in terms of a client side problem. However, in reality AJAX is vulnerable to server side vulnerabilities as well. This is 100% true for AJAX frameworks that comprise a server side component (DWR, GWT, Amazon). This type of vulnerability is also very likely to affect applications that use client only frameworks because programmers tend to shift the application logic from the server to the client, and they sometimes shift security logic together with it. The result is that the server is left vulnerable to direct attacks that bypass the "legitimate" client side code.
What do you think about the full disclosure of vulnerabilities?
The guiding principle of the Imperva Application Defense Center (ADC) is to protect customers. As a result, we follow the vulnerability disclosure protocol of each platform we research. For example, when working with commercial software platforms like Oracle, IBM DB2, Sybase, and Microsoft SQL Server, the ADC submits vulnerability discoveries to the appropriate vendor so they can issue a patch or fix in a timely fashion. Once a patch has been released, the ADC publishes a free technical advisory that explains the vulnerability and how to mitigate it. To protect our customers until a patch is released, Imperva automatically updates our SecureSphere Database security appliances and web application firewalls with the means to identify and mitigate the attack.
Spotlight

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





