Skip to main content

Responsible disclosure of latest named vulnerability, 'httpoxy'

posted onJuly 19, 2016
by l33tdawg

The latest branded vulnerability, "httpoxy," comes complete with a website and Twitter feed -- but this time, experts say, researchers performed the disclosure responsibly.

The researchers discovered that the httpoxy vulnerabilities have been described many times since as early as 2001 and found in apps written with PHP, Python and Go, and could potentially be common in other programming languages. The httpoxy vulnerabilities don't allow remote code execution, but they do enable man-in-the-middle (MiTM) attacks against vulnerable web services.

"Httpoxy is a direct [man-in-the-middle attack]. But only for outgoing requests the server makes, and only for those made from the handler for an httpoxy-crafted request," said Dominic Scheirlinck, principal engineer, for the Auckland, New Zealand e-commerce firm Vend. Scheirlinck is the lead for the httpoxy disclosure team. "At this stage, we think you'd need to chain httpoxy with some other exploit to achieve further results, like affecting the requests made for other users."

Source

Tags

Security

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Simplenews subscription

Stay informed - subscribe to our newsletter.
The subscriber's email address.
Keeping Knowledge Free for Over a Decade

Copyright © 2018 Hack In The Box. All rights reserved.

36th Floor, Menara Maxis, Kuala Lumpur City Centre 50088 Kuala Lumpur Malaysia
Tel: +603-2615-7299 Fax: +603-2615-0088