HTTP header Alt-Svc can be used for scanning internal network ports

Researchers from Boston University krijuan attack method
(CVE-2019-11728), që lejon scan IP addresses and open network ports in the user's internal network, isolated from the external network by a firewall, or on the current system (localhost). The attack can be executed when a specially crafted page is opened in the browser. The proposed technique is based on using the HTTP header Alt-Svc (HTTP Alternate Services, RFC-7838). The issue manifests in Firefox, Chrome, and browsers based on their engines, including Tor Browser and Brave.

The Alt-Svc header allows the server to determine an alternative way to access the site and instructs the browser to redirect the request to a new host, for example, for load balancing. It is also possible to specify a network port for tunneling, such as specifying ‘Alt-Svc: http/1.1="other.example.com:443";ma=200’ instructing the client to connect to the host other.example.org using network port 443 and the HTTP/1.1 protocol to obtain the requested page. The ‘ma’ parameter sets the maximum lifetime of the redirect. In addition to HTTP/1.1, supported protocols include HTTP/2-over-TLS (h2), HTTP/2-over plain text (h2c), SPDY (spdy), and QUIC (quic), using UDP.

HTTP header Alt-Svc can be used for scanning internal network ports

To scan addresses, the attacker's site can sequentially iterate through the interesting addresses of the internal network and network ports, using the delay between repeated requests as a signature.
If the redirected resource is unavailable, the browser instantly receives an RST packet in response and immediately marks the alternative service as unavailable and resets the lifetime specified in the request.
If the network port is open, it takes longer to complete the connection (an attempt will be made to establish a connection with the corresponding packet exchange), and the browser will not respond instantly.

Për të marrë informacion rreth kontrollit, sulmuesi mund menjëherë të ridrejtojë përdoruesin në një faqe të dytë, e cila në titullin Alt-Svc referohet në një host funksional të sulmuesit. Nëse shfletuesi i klientit dërgon një kërkesë në këtë faqe, atëherë mund të mendohet se ridrejtimi i kërkesës së parë të Alt-Svc është anuluar dhe hosti dhe porta e kontrolluar janë të paarritshme. Nëse nuk ka pasur një kërkesë, atëherë të dhënat për ridrejtimin e parë nuk janë skaduar ende dhe lidhja është krijuar.

Metoda e specificuar gjithashtu lejon kontrollin e porteve rrjetësore, të cilat janë të listuara në blacklistin e shfletuesit, siç janë portat e serverëve të postës. Sulmi që funksionon është përgatitur duke përdorur iframe-in e vendosur në trafik të viktimës dhe duke aplikuar protokollin HTTP/2 në Alt-Svc për Firefox dhe QUIC për skanimin e porteve UDP në Chrome. Në Tor Browser, sulmi nuk mund të përdoret në kontekstin e rrjetit të brendshëm dhe localhostit, por është i përshtatshëm për organizimin e skanimit të fshehtë të hosteve të jashtëm përmes nyjës dalëse të Tor. Problemi me skanimin e porteve tashmë është eliminuar në Firefox 68.

Titulli Alt-Svc gjithashtu mund të aplikohet:

  • NĂ« organizimin e sulmeve DDoS. PĂ«r shembull, pĂ«r TLS, ridrejtimi mund tĂ« sigurojĂ« njĂ« nivel pĂ«rforcimi deri nĂ« 60 herĂ«, pasi kĂ«rkesa fillestare e klientit zĂ« 500 byte, ndĂ«rsa pĂ«rgjigjja me certifikat Ă«shtĂ« rreth 30 Kb. Duke gjeneruar kĂ«rkesa tĂ« tilla nĂ« cikĂ«l nĂ« shumĂ« sisteme klienti, mund tĂ« arrihet shfrytĂ«zimi i burimeve rrjetĂ«sore tĂ« disponueshme tĂ« serverit;

    HTTP header Alt-Svc can be used for scanning internal network ports
  • PĂ«r tĂ« anashkaluar mekanizmat e mbrojtjes nga phishing dhe malware, tĂ« ofruara nga shĂ«rbime si Safe Browsing (ridrejtimi nĂ« njĂ« host tĂ« dĂ«mshĂ«m nuk çon nĂ« njĂ« paralajmĂ«rim);
  • PĂ«r organizimin e ndjekjes sĂ« lĂ«vizjes sĂ« pĂ«rdoruesit. QĂ«llimi i metodĂ«s Ă«shtĂ« vendosja e iframe, e cila referohet nĂ« Alt-Svc tek njĂ« proces ndjekjeje tĂ« jashtĂ«m, thirrja e tĂ« cilit bĂ«het pavarĂ«sisht nga aktivizimi i mjeteve tĂ« mbrojtjes nga ndjekĂ«sit. Gjithashtu Ă«shtĂ« e mundur ndjekja nĂ« nivelin e ofruesve pĂ«rmes pĂ«rdorimit nĂ« Alt-Svc tĂ« njĂ« identifikuesi unik (IP:port tĂ« rastĂ«sishĂ«m si identifikues) me analizĂ«n e tij tĂ« mĂ«vonshme nĂ« trafik transit;

    HTTP header Alt-Svc can be used for scanning internal network ports

    HTTP header Alt-Svc can be used for scanning internal network ports
  • PĂ«r tĂ« nxjerrĂ« informacione mbi historinĂ« e lĂ«vizjeve. Duke vendosur nĂ« faqen tuaj njĂ« iframe me njĂ« kĂ«rkesĂ« pĂ«r imazhe nga njĂ« faqe e caktuar qĂ« pĂ«rdor Alt-Svc dhe duke analizuar gjendjen e Alt-Svc nĂ« trafikun, njĂ« sulmues qĂ« ka mundĂ«sinĂ« tĂ« analizojĂ« trafikun transit mund tĂ« pĂ«rfundojĂ« se pĂ«rdoruesi mĂ« parĂ« ka vizituar atĂ« faqe.
  • Zhurma e logeve tĂ« sistemeve tĂ« identifikimit tĂ« sulmeve. NĂ«pĂ«rmjet Alt-Svc mund tĂ« shkaktoni njĂ« valĂ« kĂ«rkimesh ndaj sistemeve tĂ« dĂ«mtuara nĂ« emĂ«r tĂ« pĂ«rdoruesit dhe tĂ« krijoni njĂ« pamje tĂ« sulmeve falso pĂ«r tĂ« fshehur informacionet reale mbi njĂ« sulm tĂ« vĂ«rtetĂ«.

Burimi: opennet.ru

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster