Feeds

Web Services to aid DOS attacks

Security wrapper

  • alert
  • submit to reddit

Protecting users from Firesheep and other Sidejacking attacks with SSL

The development of web services standards allows us to contemplate the creation of business applications that are based upon collections of loosely-coupled components served up by a variety of third parties. The question that arises is just who it is that is going to expose themselves to denial of service attacks in this way.

There are many reasons why web services activity is currently restricted to use within the intranet. Mainly, the lack of experience dictates that most development is experimental. Also, there is a shortage of security and manageability within the standards that makes the publication of web services outside the firewall a pretty scary option.

However, if we look forward to a time when these wrinkles have been ironed out, we can see an opportunity for publicly exposed functions to be used to swamp the servers that host them.

The nice thing about the web services standards is that they are designed to help an outside party who wants to find and execute a piece of functionality.

First of all, UDDI will help your attacker to find any services that have been published within the networked environment and then WSDL will provide the details required to make it work.

With the aid of a little SOAP, the service can be executed on the host server and the DOS attack has begun. Swamp the web services with requests and there's a pretty good chance that the servers will fall flat on their backs.

We can argue, of course, that nobody will even contemplate the global publication of web services until a cosy wrapper of security exists around them. However, there needs to be strong identity management that ensures that the host trusts us before giving out the information needed to execute the functions.

One obvious solution is a directory implementation that requires the user is properly authenticated before even knowing which services are available.

This does defeat the idea that any component can be available to anybody but it is only the technology purists that believe this to be practical. A directory offers the foundation required to implement the management features necessary.

In the real world, even globally available web services are going to need registration information - not only for security purposes but also to make sure that users pay for their use. You didn't really think you'd get all this for free. Did you?

©IT-Analysis.com.

Website security in corporate America

More from The Register

next story
Hey, Scots. Microsoft's Bing thinks you'll vote NO to independence
World's top Google-finding website calls it for the UK
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Huawei ditches new Windows Phone mobe plans, blames poor sales
Giganto mobe firm slams door shut on Microsoft. OH DEAR
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
OECD lashes out at tax avoiding globocorps' location-flipping antics
You hear that, Amazon, Google, Microsoft et al?
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.