Security Holes Found in some DLP Products

Security Holes Found in some DLP Products

Security Holes Found in some DLP ProductsTwo researchers have discovered multiple flaws in commercial and open-source data loss prevention (DLP) products, according to a report.

Zach Lanier, senior security researcher at Duo Security, and Kelly Lum, security engineer with Tumblr, claim to have discovered vulnerabilities in cross-site scripting (XSS) and cross-site request forgery (CSRF) in four commercial DLP products and one open-source tool. In order to draw attention to the matter, they have opted not to name names until their keynote at the Black Hat USA conference this week. Their speech is titled “Stay Out of the Kitchen: A DLP Security Bake-Off,” and will provide proof-of-concept attack examples.

The duo says they weren’t surprised to find flaws in these systems. “It was not a huge shock,” said Lum. “But I was a little surprised that some of the vulnerabilities were very simple, which means they should be easily fixed. It’s curious that they could have been easily avoided in the first place.”

The majority of the flaws were found in the web-based interfaces of the products, such as the administrative panels. “Some were endpoint and some were network-based,” said Lanier. “We also evaluated document parsing pieces that classify and protect the data.

These flaws wouldn’t allow for bypassing abilities, but the researchers do say they found flows that would allow an attacker to reconfigure or change the behavior of the DLP system so that it no longer monitors data leaks.

About the Author

Matt Holden is an Associate Content Editor for 1105 Media, Inc. He received his MFA and BA in journalism from Ball State University in Muncie, Indiana. He currently writes and edits for Occupational Health & Safety magazine, and Security Today.

Featured

Featured Cybersecurity

Webinars

New Products

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3

  • Camden Door Controls ‘SER” Surface Boxes and Extension Rings

    Camden Door Controls ‘SER” Surface Boxes and Extension Rings

    Camden Door Controls has introduced new ‘SER” surface boxes and extension rings that provide a complete solution for new construction. In addition, they provide a simple and robust solution when replacing round wired and manual push plate switches with either Camden’s wired or wireless SureWave™ no-touch switches or Kinetic™ no-battery wireless switches. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3