Learning Objective 5.1.A: Explain how adversaries can exploit application and file vulnerabilities to cause loss, damage, disruption, or destruction.
- 5.1.A.1 An adversary can read any unencrypted files if they have access to the device or drive storing the files.
- 5.1.A.2 Computers have standard users and administrative users. Administrative users have access to control system settings and can typically access any files or applications on a system. If regular users are given administrative privileges on a computer, and an adversary can compromise a user’s account, then the adversary will have elevated privileges on the system.
- 5.1.A.3 When access control settings are weakly configured, many users often have permission to view and sometimes even edit files on a system. Adversaries can take advantage of weak access control settings to steal or destroy files or disrupt an application.
Learning Objective 5.1.B: Explain how application attacks exploit vulnerabilities.
- 5.1.B.1 Applications are programs that run instructions on computers; they are executable data. Some applications run locally on a user’s computer, while other applications, like web applications, run on a server and are accessed by users through a network.
- 5.1.B.2 Many applications take user input through open-ended input fields where users can type characters (e.g., letters, numbers, punctuation). Developers should include user input checks in their application, such as numeric input when asked for a number of items, to ensure that the user input matches what is expected; the application should reject input outside of the expected parameters. This process of verifying that user input meets expected criteria before processing it is called data validation. Applications that fail to validate user input are vulnerable to injection-type attacks, where adversaries insert unexpected character strings in input fields to alter the behavior of a program.
- 5.1.B.3 Structured query language (SQL) is a computer language used to request information from databases and make changes to databases or entries in databases. Applications that query a database using unvalidated or unsanitized input from users are vulnerable.
- 5.1.B.4 An SQL-injection attack places SQL commands and control characters into a user-input field in an application, which can lead to a breach of confidentiality by causing the application to return more information than it should, or a breach of integrity by modifying or deleting data in the database.
- 5.1.B.5 Websites are written using hypertext markup language (HTML), and many websites use Javascript to create dynamic content on websites or web applications. Because Javascript commands run in the browser of the user visiting the website, those commands can access sensitive data stored in the browser like usernames, passwords, and cryptographic keys.
- 5.1.B.6 A cross site scripting (XSS) attack injects malicious code into a website that a user’s browser then executes. The malicious code can be embedded in a link the user clicks (a Type I or Reflected XSS attack) or it can be inserted onto a website through a comment field, forum post, or visitor log, which would affect any user visiting that website (a Type II or Stored XSS attack).
- 5.1.B.7 When applications take user input, that input is written to a buffer. A buffer is a designated section of computer memory with a fixed size. If the amount of data the user enters exceeds the size of the buffer, it can overflow into adjacent memory locations and overwrite other parts of the computer’s memory.
- 5.1.B.8 A buffer overflow attack feeds more data into memory than was allotted, which can cause a system to crash or to execute code outside the scope of a program’s security policy, effectively allowing the adversary to perform unauthorized actions on a computer, such as accessing, modifying, or deleting files.
- 5.1.B.9 The files that run web applications are stored in directories on servers. When users access web applications, their browsers send GET requests using hypertext transfer protocol (HTTP). A GET request accesses a file somewhere in the filesystem of the server.
- 5.1.B.10 In a directory traversal attack, adversaries modify URLs and GET requests to attempt to access sensitive data (e.g., usernames and passwords) on a server’s file system.
- Illustrative examples for 5.1.B.10:
- A web server stores images for a website it hosts in the /var/www/images/ directory. An adversary modifies a URL requesting an image to ../../../etc/passwd. The .. moves one directory up in the file system; so the three consecutive .. returns the path to the root, and from there the adversary is attempting to access the passwd file that would return a list of all the authorized usernames on the device.
- Illustrative examples for 5.1.B.10:
Learning Objective 5.1.C: Assess and document risks from application and data vulnerabilities.
- 5.1.C.1 Data security risks can involve a compromise of confidentiality when unauthorized persons can access sensitive data, integrity when data can be manipulated or altered from its intended state, and availability when data can be destroyed or encrypted to prevent others from accessing it.
- 5.1.C.2 High risks from data vulnerabilities often involve highly sensitive data (e.g., data that is governed by laws or regulations) that could be compromised through a highly likely exploit.
- Illustrative examples for 5.1.C.2:
- The company developing the next jet engine that will be used by the Air Force in its planes is storing the technical specifications for the engine on an unencrypted drive.
- Illustrative examples for 5.1.C.2:
- 5.1.C.3 Moderate risks from data vulnerabilities often involve sensitive data not having strong enough encryption or strict enough access controls.
- Illustrative examples for 5.1.C.3:
- A company stores its customers’ PII in a spreadsheet, and the spreadsheet is encrypted using a small key.
- Illustrative examples for 5.1.C.3:
- 5.1.C.4 Low risks from data vulnerabilities often involve less sensitive information being encrypted with shorter keys or having access controls that are not strict enough.
- Illustrative examples for 5.1.C.4:
- An organization’s CEO stores his private memos to his executive staff on a company share drive that is unencrypted and has no access controls.
- Illustrative examples for 5.1.C.4:
מטרת למידה 5.1.A: הסבר כיצד תוקפים יכולים לנצל פגיעות באפליקציות ובקבצים כדי לגרום לאובדן, נזק, הפרעה או הרס.
- 5.1.A.1 תוקף יכול לקרוא כל קובץ שאינו מוצפן אם יש לו גישה למכשיר או לכונן האוחז את הקבצים.
- 5.1.A.2 למחשבים יש משתמשים רגילים ומשתמשים מנהלים. למשתמשים מנהלים יש גישה להגדרות שליטה במערכת והם יכולים בדרך כלל לגשת לכל הקבצים או האפליקציות במערכת. אם משתמשים רגילים מקבלים זכויות מנהל במחשב, ובתוקף מצליח לפגוע בחשבון המשתמש, אז התוקף יקבל זכויות מוגברות במערכת.
- 5.1.A.3 כאשר הגדרות בקרת הגישה חלשות, למשתמשים רבים יש לעיתים קרובות רשות לצפות ולפעמים גם לערוך קבצים במערכת. תוקפים יכולים לנצל הגדרות בקרת גישה חלשות לגנוב או להרס קבצים או להפריע באפליקציה.
מטרת למידה 5.1.B: הסבר כיצד תקיפות באפליקציות מנצלות פגיעות.
- 5.1.B.1 אפליקציות הן תוכניות המבצענות פקודות במחשבים; הן נתונים ביצועיים. חלקן רצה על מחשב המשתמש המקומי, בעוד שאחרות, כמו אפליקציות אתר, רוצות על שרত ומוגשות למשתמשים דרך רשת.
- 5.1.B.2 למספר אפליקציות יש שדות כניסה פתוחים בהם משתמשים יכולים להקליד תווים (למשל, אותיות, מספרים, סימני פיסוק). מת開發ים צריכים לכלול בדיקות כניסת משתמש באפליקציה, כגון כניסה מספרית כאשר מבוקש מספר פריטים, כדי להבטיח שכניסת המשתמש תתאים למצופה; האפליקציה אמורה לדחות כניסה מחוץ לפארמטרים המצופים. תהליך זה של וידוא שכניסת המשתמש עומדת בקריטריונים מצופים לפני העיבוד נקרא תקפות נתונים. אפליקציות שלא מבצענות תקפות בכניסת המשתמש הן פגיעות לתקיפות מסוג הזרקת קוד, שבהן תוקפים מזריקים שרשרות תווים בלתי צפויות בשדות הכניסה כדי לשנות את התנהגות התוכנית.
- 5.1.B.3 שפת SQL (Structured Query Language) היא שפת מחשב המשמשת לבקשת מידע ממאגרי נתונים ולביצוע שינויים במאגרי נתונים או בהקלטות במאגר. אפליקציות המבקשות מידע ממאגר נתונים באמצעות כניסה שאינה תקפה או לא נוקאת משמשת המשתמשים הן פגיעות.
- 5.1.B.4 תקפת הזרקת SQL (SQL-injection) מניחה פקודות SQL ותווים שלט בשדה כניסת משתמש באפליקציה, מה שעשוי להוביל לפגיעה בסודיות על ידי גרירה לאפליקציה להחזיר יותר מידע ממה שצריך, או לפגיעה באמינות על ידי שינוי או מחיקת נתונים במאגר הנתונים.
- 5.1.B.5 אתרים נכתבים באמצעות HTML (hypertext markup language), והרבה אתרים משתמשים ב-Javascript ליצירת תוכן דינמי באתרים או באפליקציות אתר. מכיוון שפקודות Javascript רוצות בדפדפן של המשתמש המבקר באתר, פקודות אלו יכולות לגשת למידע רגיש שנשמר בדפדפן כמו שמות משתמש, סיסמאות ומפתחות קריפטוגרפיים.
- 5.1.B.6 תקפת XSS (cross site scripting) מזריקה קוד רע לאתר שהדפדפן של המשתמש מבצע לאחר מכן. הקוד הרע יכול להיות משולב בקישור שמשתמש לוחץ עליו (תקפת Type I או Reflected XSS) או שהוא יכול להיות מוזרק לאתר דרך שדה תגובה, פרסום בפורום או לוג ביקורים, מה שישפיע על כל משתמש המבקר באתר הזה (תקפת Type II או Stored XSS).
- 5.1.B.7 כאשר אפליקציות לוקחות כניסת משתמש, כניסה זו נכתבת לבאפר. באפר הוא אזור מוגדר בזיכרון המחשב בגודל קבוע. אם כמות הנתונים שמשתמש מכניס עולה על גודל הבאפר, היא עלולה להתפשט לזיכרון סמוך ולהחליף חלקים אחרים של זיכרון המחשב.
- 5.1.B.8 תקפת overflow באפר (buffer overflow) מזריקה יותר נתונים לזיכרון מאשר הוקצב, מה שעשוי לגרום למערכת לקרוש או לבצע קוד מחוץ לתחום מדיניות הביטחון של התוכנית, ומאפשר בפועל לתוקף לבצע פעולות בלתי מורשות במחשב, כגון גישה, שינוי או מחיקת קבצים.
- 5.1.B.9 הקבצים המפעילים אפליקציות אינטרנט מאוחסנים בתיקיות על שרתים. כאשר משתמשים נכנסים לאפליקציות אינטרנט, הדפדפנים שלהם שולחים בקשות GET באמצעות פרוטוקול העברת טקסט היפר (HTTP). בקשת GET גישה לקובץ כלשהו במערכת הקבצים של השרת.
- 5.1.B.10 בתקיפת דילוג בתיקיות, מתקיפים מעבירים את הכיתובים (URLs) ואת הבקשות GET כדי לנסות לגשת למידע רגיש (למשל, שמות משתמש וסיסמאות) במערכת הקבצים של השרת.
- דוגמאות להמחיה עבור 5.1.B.10:
- שרת אינטרנט מאחסן תמונות לאתר שהוא מארח בתיקיה /var/www/images/. מתקיף מעביר כיתוב (URL) בבקשה לתמונה ל- ../../../etc/passwd. ה- .. מייצג מעבר תיקיה אחת כלפי מעלה במערכת הקבצים; לכן, שלושת ה- .. הרציפים מחזירים את הנתיב לשורש, ומשם המתקיף מנסה לגשת לקובץ passwd שיחזיר רשימה של כל שמות המשתמשים המורשים על המכשיר.
- דוגמאות להמחיה עבור 5.1.B.10:
מטרות לימוד 5.1.C: הערכה ותיעוד סיכונים הנובעים ממעבירות באפליקציות ובנתונים.
- 5.1.C.1 סיכוני אבטחת נתונים עשויים לכלול פגיעה בסודיות כאשר אנשים בלתי מורשים יכולים לגשת למידע רגיש, שלמות כאשר נתונים ניתנים לעיוות או שינוי מהמצב המקורי שלהם, וזמינות כאשר נתונים ניתנים להריסה או הצפנה כדי למנוע מגישה אליהם.
- 5.1.C.2 סיכונים גבוהים ממעבירות נתונים כוללים לעיתים קרובות נתונים רגישים מאוד (למשל, נתונים הנשלטים על ידי חוקים או תקנות) שעשויים להיות חשופים דרך ניצול סביר מאוד.
- דוגמאות להמחיה עבור 5.1.C.2:
- החברה המפתחת את מנוע הסילון הבא שימשמש במטוסי צה"ל מאחסנת את המפרטים הטכניים של המנוע על דיסק שאינו מצופה הצפנה.
- דוגמאות להמחיה עבור 5.1.C.2:
- 5.1.C.3 סיכונים בינוניים ממעבירות נתונים כוללים לעיתים קרובות נתונים רגישים שאין להם הצפנה חזקה מספיק או הגבלות גישה מחמירות מספיק.
- דוגמאות להמחיה עבור 5.1.C.3:
- חברה מאחסנת את המידע האישי של לקוחותיה (PII) בגיליון עבודה, והגיליון מצופה הצפנה בעזרת מפתח קטן.
- דוגמאות להמחיה עבור 5.1.C.3:
- 5.1.C.4 סיכונים נמוכים ממעבירות נתונים כוללים לעיתים קרובות מידע פחות רגיש המצופה במפתחים קצרים או עם הגבלות גישה שאינן מחמירות מספיק.
- דוגמאות להמחיה עבור 5.1.C.4:
- נשיא מועצה מנהלת מאחסן את המכתבים הפרטיים שלו לצוות המנהלים בחברה על נתיב שיתוף בחברה שאינו מצופה הצפנה ואינו כולל הגבלות גישה.
- דוגמאות להמחיה עבור 5.1.C.4:


