Posted on July 20, 2022
I recently created a fictional Juice Shop to demonstrate an innovative isolation-based solution for protecting web applications from the most dangerous threats, as ranked in the OWASP Top 10. The Juice Shop app, which he developed on the HyperQube test platform, is designed to be super vulnerable – with “as many holes as Swiss cheese.”
In the short demo below, the first of a series in which I attack my own Juice Shop in various ways, I present a scenario for “Broken Access Control” – #1 in OWASP’s 2021 list.
Without proper protection, a directory traversal attack, in which a threat actor simply modifies the URL to bypass security controls and access files and directories that are exposed by the application’s backend. This method is one of the most common attacks enabled by broken access control. It is among the easiest ways to gain access to files on a server that is running an application and once in, steal data, modify files, or possibly find valuable exposed information on the backend of the application.
Ericom Web Application Isolation (WAI) is an innovative cloud-delivered security solution that isolates web/cloud applications and their APIs from cyber-threats – think of it as a “next-gen” WAF solution. WAI can be used to apply policy-based restrictions that control which links a user can reach, and what actions they can – and cannot – take. But don’t take our word for it. Check out the demo below!
“Operation Duck Hunt” Shuts Down QakBot Botnet
The FBI-led takedown of Qakbot was an operation that involved seven countries. Malware was removed from 700,000 computers. But don’t think all that makes you safe.
How GenAI is Supercharging Zero-Day Cyberattacks
Generative AI empowers its users to work fast, better and more efficiently. Alas, this includes cybercriminals, who are using malicious GenAI platforms to accelerate zero-day exploit creation.
Cybercriminals Disdain the Law, But Find Law Firms Attractive
Cybercriminals love the multiplier effect they get from attacking law firms: Hack in, and they get firm data PLUS juicy confidential client info.