Security Holes Found in some DLP Products

Security Holes Found in some DLP Products

Security Holes Found in some DLP ProductsTwo researchers have discovered multiple flaws in commercial and open-source data loss prevention (DLP) products, according to a report.

Zach Lanier, senior security researcher at Duo Security, and Kelly Lum, security engineer with Tumblr, claim to have discovered vulnerabilities in cross-site scripting (XSS) and cross-site request forgery (CSRF) in four commercial DLP products and one open-source tool. In order to draw attention to the matter, they have opted not to name names until their keynote at the Black Hat USA conference this week. Their speech is titled “Stay Out of the Kitchen: A DLP Security Bake-Off,” and will provide proof-of-concept attack examples.

The duo says they weren’t surprised to find flaws in these systems. “It was not a huge shock,” said Lum. “But I was a little surprised that some of the vulnerabilities were very simple, which means they should be easily fixed. It’s curious that they could have been easily avoided in the first place.”

The majority of the flaws were found in the web-based interfaces of the products, such as the administrative panels. “Some were endpoint and some were network-based,” said Lanier. “We also evaluated document parsing pieces that classify and protect the data.

These flaws wouldn’t allow for bypassing abilities, but the researchers do say they found flows that would allow an attacker to reconfigure or change the behavior of the DLP system so that it no longer monitors data leaks.

About the Author

Matt Holden is an Associate Content Editor for 1105 Media, Inc. He received his MFA and BA in journalism from Ball State University in Muncie, Indiana. He currently writes and edits for Occupational Health & Safety magazine, and Security Today.

Featured

New Products

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • Zenitel Cloud RMM

    Zenitel Cloud Remote Monitoring & Management (RMM)

    Enhance operational uptime and slash maintenance costs across multi-site environments with secure, centralized cloud-based system diagnostics and lifecycle management.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.