Showing posts with label Opera. Show all posts
Showing posts with label Opera. Show all posts

Dubious HTTP III - Playing With Content-Length

The Content-Length header describes the size of the content, so there should be at most one. But what happens, when multiple Content-length headers get sent?

To determine the behavior of the browsers I tested with:
  • Microsoft Internet Explorer (MSIE) versions 8 and 10
  • Firefox 22
  • Google Chrome 28
  • Opera 12.16 (before WebKit)
  • Rekonq (KDE project) 2.2.1 - Konqueror (KDE) seems to behave the same

What's It Take To Trust A Digitally Signed Program?

http://www.darkreading.com/attacks-breaches/whats-it-take-to-trust-a-digitally-signe/240157741
Opera Software
The Opera Software breach that came to light last week after attackers compromised Opera's network in order to steal an expired certificate and use it to sign malware for distribution dredges up some serious concerns from security professionals about the amount of trust that organizations put into legitimately signed programs.

In particular, the attack brought up fears about auto-updating processes given that this particular strike used Opera's updating infrastructure to automatically push out updates to customers.

"Attacks that subvert the methods used to validate programs and their updates are very troubling," says Jean Taggart, senior researcher at Malwarebytes. "They serve as a strong reminder to practice defense in depth."

The Opera attack is hardly an exception in today's malicious hacking standard operating procedures.



Opera breached, possibly spreads malware

On June 19th Opera Security group uncovered, halted and contained a targeted attack on their internal network infrastructure. Their systems have been cleaned and there is no evidence of any user data being compromised. Opera staff is working with the relevant authorities to investigate its source and any potential further extent.

The current evidence suggests a limited impact. The attackers were able to obtain at least one old and expired Opera code signing certificate, which they have used to sign some malware. This has allowed them to distribute malicious software which incorrectly appears to have been published by Opera Software, or appears to be the Opera browser.

Opera Software logo
Opera software logo
Security breach stopped | Opera Security group