[x] ปิดหน้าต่างนี้
 

 

  
Veraport: Inside Korea’s Dysfunctional Application Management
โดย : Jani   เมื่อวันที่ : ศุกร์ ที่ 21 เดือน สิงหาคม พ.ศ.2569   


<p><img src="https://cdn.cosmos.so/28f362bf-62df-4f3f-98e6-af43397f3647" loading="lazy" style="clear:both; float:right; padding:10px 0px 10px 10px; border:0px; max-width: 350px;">Note: This text is also obtainable in Korean. As mentioned before, South Korea_s banking websites demand installation of varied so-referred to as security purposes. At the identical time, we_ve seen that these applications like TouchEn nxKey and IPinside lack auto-update functionality. So even in case of safety points, it is sort of inconceivable to ship updates to customers timely. And that_s only two purposes. Korea_s banking web sites usually expect round five functions, and it will be totally different applications for different websites. That_s lots of applications to install and to sustain-to-date. Luckily, the Veraport application by Wizvera will take care of that. This application will mechanically set up every little thing mandatory to use a selected webpage. And it will even set up updates if deemed obligatory. If this appears like a variety of energy: that_s because it is. And so Veraport already made the information because the vehicle of an assault by North Korean hackers.</p><br><p><img src="https://live.staticflickr.com/618/20658692715_619048156e_o.jpg" alt="Kos Island" loading="lazy" style="clear:both; float:right; padding:10px 0px 10px 10px; border:0px; max-width: 350px;">Back then all people was quick to shift the blame to the compromised internet servers. I now took a deeper dive into how Veraport works and got here to <a href="http://www.qingdaomop.com/?204701">the transfer agreement</a> conclusion: its approach is inherently harmful. As of Veraport 3.8.6.5 (released on February 28), all the reported security issues seem to be mounted. Getting customers to replace will take a very long time nevertheless. Also, the harmful strategy of allowing Veraport customers to distribute arbitrary software program stays of course. Who has the signing keys? Veraport indicators the coverage files figuring out which applications are to be installed from the place. One root certificate nonetheless used for signature validation is using MD5 hashing and a 1024 bit strong RSA key. Such certificates have been deprecated for over a decade. HTTPS connection for downloads is just not being enforced. Even when HTTPS is used, server certificate just isn't validated. Integrity of downloaded files just isn't validated appropriately. Application signature validation is trivially circumvented, and while hash-based mostly validation is feasible this performance is essentially unused.</p><br><p>Even when integrity validation weren_t simply circumvented, Veraport leaves the choice to the person as to whether or not to proceed with a compromised binary. Download and set up of an application will be triggered without user interaction and without any seen clues. Individual web sites (e.g. banking) are nonetheless answerable for software distribution and will typically offer outdated functions, probably with known safety points. Each Veraport customer is in possession of a signing certificate that, if compromised, can signal arbitrary malicious insurance policies. There is no revocation mechanism to withdraw recognized leaked signing certificates or malicious policies. In addition to that, Veraport_s local net server on https://127.0.0.1:16106 contains vulnerabilities amounting to persistent Cross-Site Scripting (XSS) among other things. It would expose the complete listing of the processes working on the user_s machine to any webpage asking. For security applications it may also expose the applying model. Finally, Veraport is also built on high of a variety of outdated open-supply libraries with known vulnerabilities.</p><br><p>For instance, it uses OpenSSL 1.0.2j (launched 2016) for its net server and for signature validation. OpenSSL vulnerabilities are notably properly-documented - it_s a minimum of three known high-severity and 13 identified average-severity vulnerabilities for this version. The native internet server itself is mongoose 5.5 (released in 2014). And parsing of probably malicious JSON information obtained from web sites is finished via JsonCpp 0.5.Zero (launched 2010). Yes, that_s <a href="https://www.caringbridge.org/search?q=virtually%20thirteen">virtually thirteen</a> years previous. Yes, current version is JsonCpp 1.9.5 which has seen plenty of safety improvements. Login websites of South Korean banks run JavaScript code from SDKs belonging to various so-known as security applications. Each such SDK will first verify whether or not the applying is current on the user_s laptop. If it isn_t, the typical motion is redirecting the user to a download web page. This isn_t the software program vendor_s obtain page but relatively the bank_s web page. It lists all the varied functions required and expects you to obtain them. Typically, the bank_s net server doubles as the obtain server for the application.</p><br><p>A number of the software distributors don_t even have their very own obtain servers. So it most likely comes as no surprise that every one banks distribute different variations of the applications, typically years behind the present release. Also, it_s very common to seek out an outdated and hopefully unused set up page. Downloading the appliance from this page will usually still work, but it will be up to a decade previous. And whereas Busan Bank web site for instance claims to have software program packages for Linux and macOS users, these aren_t truly downloadable otherwise you get Windows software program. The one Linux bundle which could be downloaded is from 2015 and depends on NPAPI which isn_t supported by modern browsers. Obviously, customers can't be expected to deal with this whole mess. And that_s why banks sometimes additionally supply one thing known as "integrated installation." This means downloading Wizvera Veraport software and letting it do everything mandatory. Should you anticipate Veraport to know where to get the latest model of every utility and when to update them: that_s of course not it.</p>

เข้าชม : 0





Re หัวข้อ :
รูปประกอบ : Limit 100 kB
ไอคอน : ย่อหน้า จัดซ้าย จัดกลาง จัดขวา ตัวหนา ตัวเอียง เส้นใต้ ตัวยก ตัวห้อย ตัวหนังสือเรืองแสง ตัวหนังสือมีเงา สีแดง สีเขียว สีน้ำเงิน สีส้ม สีชมพู สีเทา
อ้างอิงคำพูด เพิ่มเพลง เพิ่มวีดีโอคลิป เพิ่มรูปภาพ เพิ่มไฟล์ Flash เพิ่มลิงก์ เพิ่มอีเมล์
รายละเอียด :
ใส่รหัสที่ท่านเห็นลงในช่องนี้
ชื่อของท่าน :


 
กศน.ตำบลเมืองพัทยากลาง
ถนนพัทยาสาย 3 ตำบลหนองปรือ
อำเภอบางละมุง จังหวัดชลบุรี
โทร 087-9458058
อี-เมลล์
a_rashi5@hotmail.com
Powered by MAXSITE 1.10   Modify by   chonnfe   Version 2.03