ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Flaw threatens SME security devices

Liam Tung ZDNet Australia

Published: 02 Jul 2007 17:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw affecting eight vendors' Universal Threat Management security appliances was identified by US-based security firm Calyptix last week.

Calyptix said the Universal Threat Management (UTM) devices are vulnerable to a Cross-Site Request Forgery (CSRF) attack, which means an attacker could gain control of the security device — but only if the device administrator was tricked into simultaneously viewing a hostile web page while logged into the device.

One of the affected devices is Check Point's Safe@Office, which on Friday was the only vendor to have issued a patch for the flaw. Calyptix would not release the names of other vendors until the organisations had released a patch for the flaw.

The vulnerability is a "serious threat", according to Ty Miller, chief technician at penetration-testing specialists, Pure Hacking.

Watch this

Dialogue Box
Dialogue Box 3.10: Memory lane

There are a number of runners and riders in the next-generation memory stakes; Dialogue Box has the inside track, plus highlights from series 3

View full video+

"[It] allows an attacker to exploit an authenticated section of a web application without them requiring authentic credentials," said Miller.

Industry analyst, James Turner of IBRS Consulting, said that while the vulnerability is serious, the risk of being attacked is low because only smaller organisations typically see the vulnerable devices, and the vulnerability is difficult to exploit.

"I can imagine there are easier ways of achieving a result. Some large enterprises will have deployed UTMs at remote sites but really no large enterprise is going to be using UTMs," Turner said.

Turner also believes there is "safety in numbers" because UTM use is widespread. "Statistically that reduces everyone's likelihood of being attacked, which is cold comfort for those that get attacked using this vector."

Calyptix advises users to disable JavaScript and warns against operating multiple tabs when managing a device. The company also recommends that the web-management interface should be run on a non-standard address. In addition, it warns that any device more than a few years' old are likely be vulnerable to the flaw.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
1 out of 4 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Proposals Development Associate, CRO, Berkshire, 30,000

You will also negotiate all aspects, or contract components and amendments, of contracts directly with vendors and/or sponsors in a professional ...

Embedded C/ Device Drivers/ Networking - Linux and Derby

An Embedded Software Engineer is needed in the Derby area to join a huge multi-national organisation that specialises in innovative product design ...

Embedded Engineer - Device Driver - Linux - 42k

Have you got strong Embedded experience? Do you want a career that focuses on C programming and fantastic career progression? Is Derby the location ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment