Security Holes Found in some DLP Products

Security Holes Found in some DLP Products

Security Holes Found in some DLP ProductsTwo researchers have discovered multiple flaws in commercial and open-source data loss prevention (DLP) products, according to a report.

Zach Lanier, senior security researcher at Duo Security, and Kelly Lum, security engineer with Tumblr, claim to have discovered vulnerabilities in cross-site scripting (XSS) and cross-site request forgery (CSRF) in four commercial DLP products and one open-source tool. In order to draw attention to the matter, they have opted not to name names until their keynote at the Black Hat USA conference this week. Their speech is titled “Stay Out of the Kitchen: A DLP Security Bake-Off,” and will provide proof-of-concept attack examples.

The duo says they weren’t surprised to find flaws in these systems. “It was not a huge shock,” said Lum. “But I was a little surprised that some of the vulnerabilities were very simple, which means they should be easily fixed. It’s curious that they could have been easily avoided in the first place.”

The majority of the flaws were found in the web-based interfaces of the products, such as the administrative panels. “Some were endpoint and some were network-based,” said Lanier. “We also evaluated document parsing pieces that classify and protect the data.

These flaws wouldn’t allow for bypassing abilities, but the researchers do say they found flows that would allow an attacker to reconfigure or change the behavior of the DLP system so that it no longer monitors data leaks.

About the Author

Matt Holden is an Associate Content Editor for 1105 Media, Inc. He received his MFA and BA in journalism from Ball State University in Muncie, Indiana. He currently writes and edits for Occupational Health & Safety magazine, and Security Today.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West
  • Live From ISC West 2024: Post-Show Recap

    ISC West 2024 is complete. And from start to finish, the entire conference was a huge success with almost 30,000 people in attendance. Read Now

    • Industry Events
    • ISC West
  • ISC West 2024 is a Rousing Success

    The 2024 ISC West security tradeshow marked a pivotal moment in the industry, showcasing cutting-edge technology and innovative solutions to address evolving security challenges. Exhibitors left the event with a profound sense of satisfaction, as they witnessed a high level of engagement from attendees and forged valuable connections with potential clients and partners. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection. 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3