| By Lori MacVittie | Article Rating: |
|
| November 6, 2009 03:30 PM EST |
Yesterday the blogosphere, twittosphere, and other-spheres were abuzz when a new TLS renegotiation man-in-the-middle attack was disclosed.
Interestingly enough, while we were all still reading about it and figuring out all the nuances, one of our own DevCentral members was out implementing a solution.
No, he’s not a vendor with a product to worry about, he’s just a “guy” trying to defend his web site and applications from potential attacks like this one. But he’s a guy with network-side scripting in his arsenal of web application security tools, and with that and his understanding of the very well-documented vulnerability he crafted a solution.
Colin documents the iRule that addresses this vulnerability in his 20LoL post for the week, and so I won’t repost the code. You can also view the forum thread [registration required] in which “Lupo” describes and discusses the solution.
What I love about this solution is not necessarily that it solves a particular vulnerability. That’s awesome, of course, and a great thing but in the coming weeks and months we’ll see a lot of solutions that address this particular vulnerability. What I really love about this solution is the speed with which it was implemented. The vulnerability was disclosed yesterday and Lupo had a solution today, which he generously shared with thousands of others who can immediately put into use the same solution.
A lot of folks talk about agility and how solution X or Y enables organizations to respond rapidly to changing market/business conditions, but rarely do you see as solid an example as this one. From disclosure to solution in one day. That’s agility in action.
Related blogs & articles:
- Marsh Ray Discussion of TLS MiTM Vulnerability with white papers and descriptions
- Stop brute force listing of HTTP OPTIONS with network-side scripting
- I am in your HTTP headers, attacking your application
- Jedi Mind Tricks: HTTP Request Smuggling
- Clickjacking Protection Using X-FRAME-OPTIONS Available for Firefox
- I Can Has UR .htaccess File
- AJAX and Network-Side Scripting
- Understanding network-side scripting
Read the original blog entry...
Published November 6, 2009
Copyright © 2009 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Lori MacVittie
Lori MacVittie is responsible for education and evangelism of application services available across F5’s entire product suite. Her role includes authorship of technical materials and participation in a number of community-based forums and industry standards organizations, among other efforts. MacVittie has extensive programming experience as an application architect, as well as network and systems development and administration expertise. Prior to joining F5, MacVittie was an award-winning Senior Technology Editor at Network Computing Magazine, where she conducted product research and evaluation focused on integration with application and network architectures, and authored articles on a variety of topics aimed at IT professionals. Her most recent area of focus included SOA-related products and architectures. She holds a B.S. in Information and Computing Science from the University of Wisconsin at Green Bay, and an M.S. in Computer Science from Nova Southeastern University.
- Maybe Ubuntu Enterprise Cloud Makes Cloud Computing Too Easy
- Meh. It's Just Data.
- The API Is the New CLI
- Amazon Elastic Load Balancing Only Simple On the Outside
- Data Portability in The Cloud
- Study Says Economics Not A Driving Factor in Cloud Computing Adoption
- The Cloud Is Not A Synonym For Cloud Computing
- To Take Advantage of Cloud Computing You Must Unlearn, Luke
- Data as a Service Could Drastically Impact Success of SQL Injection Attacks
- Scaling Security in the Cloud: Just Hit the Reset Button
- Cloud, Standards, and Pants
- When Cloud Is Both the Wrong and the Right Solution
- If Load Balancers Are Dead Why Do We Keep Talking About Them?
- Maybe Ubuntu Enterprise Cloud Makes Cloud Computing Too Easy
- Cloud Computing versus Cloud Data Centers
- Developing APIs for the Cloud
- Does a Dynamic Infrastructure Need ARP for Applications?
- Linux is Not the Answer to Security Problems
- Excuse Me But Is That a Gazebo On Your Site?!
- Meh. It's Just Data.
- The API Is the New CLI
- The Cloud Metastructure Hubub
- Amazon Elastic Load Balancing Only Simple On the Outside
- Data Portability in The Cloud
- Disaster Recovery in a Web 2.0 World
- Finding New Life For SOA in the Cloud
- Is Social Media a Hostile Work Environment?
- Dear Slashdot: You Get What You Pay For
- Get Your SaaS Off My Cloud
- If Load Balancers Are Dead Why Do We Keep Talking About Them?
- Governance: Service Catalogs and the Cloud
- Twittergate Reveals E-Mail is Bigger Security Risk than Twitter
- Cloud Computing Is Not Burger King
- The Revolution Continues
- Differentiating the Application Network from the Network
- Two Different Sock(et)s



















