Responsible disclosure of latest named vulnerability, 'httpoxy'
The latest branded vulnerability, "httpoxy," comes complete with a website and Twitter feed -- but this time, experts say, researchers performed the disclosure responsibly.
The researchers discovered that the httpoxy vulnerabilities have been described many times since as early as 2001 and found in apps written with PHP, Python and Go, and could potentially be common in other programming languages. The httpoxy vulnerabilities don't allow remote code execution, but they do enable man-in-the-middle (MiTM) attacks against vulnerable web services.
"Httpoxy is a direct [man-in-the-middle attack]. But only for outgoing requests the server makes, and only for those made from the handler for an httpoxy-crafted request," said Dominic Scheirlinck, principal engineer, for the Auckland, New Zealand e-commerce firm Vend. Scheirlinck is the lead for the httpoxy disclosure team. "At this stage, we think you'd need to chain httpoxy with some other exploit to achieve further results, like affecting the requests made for other users."