A good read
Sabir Abdul-Haqq, Technical Writer/Publisher, Notary Public
PO Box 31022
Jackson, MS 39286
601-543-9600
601-519-0014 fax
www.egentz.com
sabir@egentz.com
-----Original Message-----
From: "Threat Monitor" <
SearchSecurity@lists.techtarget.com>
Date: Thu, 04 Mar 2010 18:10:34
To:
sabir@egentz.com<
sabir@egentz.com>
Subject: How vulnerable is your clientless SSL VPN?
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
SearchSecurity.com: Threat Monitor
March 04, 2010
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
CLIENTLESS SSL VPN VULNERABILITY AND WEB BROWSER PROTECTION
Randall Gamby, Contributor
In a recent vulnerability note, VU#261869, updated in mid-January
2010, The U.S. Computer Emergency Readiness Team (US-CERT) warned of
a clientless SSL VPN vulnerability found in many products. This SSL
VPN vulnerability could allow an attacker to bypass authentication
mechanisms or conduct other Web-based attacks.
So what's wrong with clientless SSL VPNs? First, it's important to
understand how these applications retrieve information. Many
clientless SSL VPN products -- a list of vulnerable products is
included in US-CERT's vulnerability note -- retrieve content from
different intranet sites and then present a consolidated view of the
content, as if it were coming from a single source: in this case,
from the SSL VPN service. This conjoined content circumvents the Same
Origin Policy, which is an important security concept for a number of
browser-side programming languages, such as JavaScript.
Read more:
http://go.techtarget.com/r/11009934/8294342
Get this tip via our RSS feed:
http://go.techtarget.com/r/11009935/8294342
Listen to this tip as an MP3:
http://go.techtarget.com/r/11009936/8294342
ALSO ON
SEARCHSECURITY.COM
How to set up a remote access security policy
When writing a remote access security policy, it's important to keep
data secure without interfering with employees' ability to work, but
what's the best way to achieve that balance? In this expert response,
David Mortman expalins what to include in such a policy.
http://go.techtarget.com/r/11009937/8294342
Read more about firewall controls that should be placed on a VPN:
http://go.techtarget.com/r/11009938/8294342
Sign up for more e-newsletters from SearchSecurity.com
SearchSecurity.com offers many timely and informative
newsletters.Sign up today for our weekly Network Security Tactics
tip, covering everything from network device management to intrusion
detection and NAC.
http://searchsecurity.techtarget.com/tieredRegPage/1,294138,sid14,00.html?track=NL-427&ad=752296
Edit your preferences to sign up for all our newsletters!
http://go.techtarget.com/r/11009939/8294342
:::::::::::::::::::::::::: ADVERTISEMENT :::::::::::::::::::::::::::
Sponsored by: HOUSE
How to make the most of authentication tools
http://go.techtarget.com/r/11009940/8294342
How to prevent phishing attacks with social engineering tests
http://go.techtarget.com/r/11009941/8294342
How to prepare for an information security job interview
http://go.techtarget.com/r/11009942/8294342
How to align network security with business priorities
http://go.techtarget.com/r/11009943/8294342
Follow us on Twitter!
http://go.techtarget.com/r/11009944/8294342
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
::::::::::::::::::::: ABOUT THIS E NEWSLETTER ::::::::::::::::::::::
This e-newsletter is published by SearchSecurity.com, part of the
TechTarget network. TechTarget provides IT professionals with the
resources they need to perform their jobs: Web sites, newsletters,
forums, blogs, white papers, webcasts, events and more. Copyright
2010 TechTarget. All rights reserved. Designated trademarks and
brands are the property of their respective owners.
UNSUBSCRIBE
If you no longer wish to receive Threat Monitor from SearchSecurity
go to unsubscribe:
http://SearchSecurity.com/u?em=sabir%
40egentz.com&uid=8294342&eid=752296&
Please note, unsubscribe requests may take up to 24 hours to process;
you may receive additional mailings during that time. A confirmation
e-mail will be sent when your request has been successfully
processed.
CONTACT US
SearchSecurity
Member Services
117 Kendrick Street, Suite 800
Needham, MA 02494