Major ISPs Injecting Ads, Vulnerabilities into Entire Web

執筆者
Ryan Naraine
Ryan Naraine
Published: Apr 19, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

DNS security guru Dan Kaminsky says the practice by major ISPs to deploy advertising servers within trademarked domains (on error pages, for example) can expose the entire Web to malicious hacker attacks.

Kaminsky (left), a well-known researcher who helped with the Sony rootkit investigation, says the advertising servers are impersonating, via DNS, hostnames within trademarked domains. “We have determined that these injected servers are, in fact, vulnerable to cross-site scripting attacks. Since these servers are being injected into your trademarked domains, their vulnerability can be used to attack your users and your sites,” Kaminsky said, identifying EarthLink, Verizon and Quest among the ISPs.

* Photo credit: Dave Bullock (Creative Commons 2.0)

Kaminsky demonstrated the flaw and discussed the security ramifications at the Toorcon Seattle conference this weekend.

During his talk, Kaminsky showed (.ppt file) how the vulnerable ad servers could be exploited for:

1. Arbitrary cookie retrieval. Any Web page on the Internet can retrieve all non-HTTP-only cookies from domains.

2. Fake site injection. A victim can be directed to “server2.www.realsite.com” or “server3.www.realsite.com,” which will appear to be a host in a trademarked domain. We believe any phishing attempts from this perfect-address spoofed subdomain are more likely to be successful.

3. Full-page compromise. A victim can be directed to an actual HTTP site, with all logged-in credentials, and a hacker’s attack page will still be able to fully manipulate the target site as if we ourselves were the victim. Note, while we cannot attack HTTPS resources, we can prevent upgrade from HTTP to HTTPS. This may affect any shopping carts within your sites.

In a statement sent to eWEEK’s SecurityWatch ahead of his talk, Kaminsky said:

“We believe this behavior is illustrative of the risks of violating Network Neutrality. Indeed, it is our sense that the HTTP web becomes insecurable if man-in-the-middle attacks are monetized by providers — if we don’t know what bits are going to reach the client, how can we control for flaws in those bits?“

Advertisement

Kaminsky, who worked for penetration testing and consulting firm IOActive, said he was able to use a vulnerability in the search injection framework of Earthlink to partially compromise Microsoft’s Live.com, eBay, the Associated Press, MySpace, Facebook and every other resource on the Web.

“Whereas Comcast outsources the operation of at least parts of their Washington network to EarthLink (who themselves are using equipment from a company called BareFruit), this is potentially affecting millions of users,” he added.

Threat Level’s Ryan Singel reported that the BareFruit vulnerability was quietly patched on April 18, 2008, a day before Kaminsky’s talk. More from Brian Krebs at SecurityFix.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。