Researchers at industrial and IoT cybersecurity firm Claroty have identified a generic method for bypassing the web application firewalls (WAFs) of several major vendors. . Claroty’s researchers discovered the method following an analysis of Cambium Networks’ wireless device management platform. They discovered a SQL injection vulnerability that could be used to obtain sensitive information, such as session cookies, tokens, SSH keys and password hashes. Exploitation of the flaw worked against the on-premises version, but an attempt to exploit it against the cloud version was blocked by the Amazon Web Services (AWS) WAF, which flagged the SQL injection payload as malicious. Further analysis revealed that the WAF could be bypassed by abusing the JSON data sharing format . JSON syntax is supported by all major SQL engines and it’s enabled by default. The link for this article located at Security Week is no longer available. . Experts at Claroty uncovered a technique that circumvents leading vendor WAF protections, highlighting weaknesses within Cambium's systems.. WAF Bypass, SQL Injection Vulnerability, Cybersecurity Research. . Brittany Day
The report -- "Intrusion Detection and Prevention for 802.11 Wireless LANs" -- has been published by Unstrung's wireless research service, Unstrung Insider, and provides detailed analysis of leading vendors and products in this rapidly developing market. . . .. The report -- "Intrusion Detection and Prevention for 802.11 Wireless LANs" -- has been published by Unstrung's wireless research service, Unstrung Insider, and provides detailed analysis of leading vendors and products in this rapidly developing market. "Many up-to-date security mechanisms cannot detect numerous types of wireless LAN attacks or policy violations because they do not offer sufficient visibility into the network and airspace," says report author Gabriel Brown. "This lack of visibility feeds suspicions that the wireless network is not business-class and could lead to serious problems as new attacks emerge against previously secure networks." . Delve into the analysis of the wireless intrusion detection landscape, offering insights into key players and their products in this rapidly advancing sector.. Wireless Security, Intrusion Prevention, Vendor Analysis, LAN Security, Wireless Detection. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.