Get a Pentest and security assessment of your IT network.

News

Clientless SSL VPNs Break Web Browser Security Models

U.S. Computer Emergency Response Team (US-CERT) says clientless SSL VPN products from multiple vendors are confirmed vulnerable. This security problem, discussed since at least 2006, could let an attacker could use these devices to bypass authentication or conduct other web-based attacks. The problem is that there is no solution to this problem. Depending on their specific configuration and location in the network these devices may be impossible to operate securely. Administrators are urged to consider the following workarounds:Limit URL rewriting to trusted domains.

Source: https://threatpost.com/clientless-ssl-vpns-break-web-browser-security-models-120109/73175/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Webroot Impact of Web-borne threats on businesses

News

UK NCSC warns of cyber attacks powered by Russia against the political system