Cyberoam intercept flaw puts enterprises at risk

Powered by SC Magazine
 

Deep packet inspection boxes spy on staff.

Enterprises using Cyberoam deep packet inspection devices could have traffic intercepted by anyone using its shared certificate.

Tor Project security researcher Runa Sandvik and OpenSSL's Ben Laurie discovered the devices used the same Certificate Authority certificate and private key.

That gaffe made it possible for any DPI box to grab traffic from employees monitored by Cyberoam devices. 

The fake certificate, credit: Tor Project

“It is therefore possible to intercept traffic from any victim (employee) of a Cyberoam device with any other Cyberoam device — or, indeed, to extract the key from the device and import it into other DPI devices, and use those for interception,” Sandvik said in an advisory.

“Victims should uninstall the Cyberoam CA certificate from their browsers and decline to complete any connection which gives a certificate warning.”

Sandvik and Laurie began researching the hole after a Tor user in Jordan reported seeing a fake Cyberoam certificate for the TorProject.org. They discovered the user’s traffic was intercepted by a Cyberoam device.

Trusted certificates had to be installed on employee machines, referred to as victims, in order for DPI to work. But that Cyberoam victims all installed the same trusted CA which would issue fake certificates was “a little surprising” Sandvik said.

The Tor boffin alerted Indian-based Cyberoam about the flaw (CVE-2012-3372) on June 30 and her intention to publish an advisory on July 3.

The company acknowledged the vulnerability and said it would investigate. The company has been contacted by SC for comment.

Users can delete the root CA by following these instructions.

Copyright © SC Magazine, Australia


Cyberoam intercept flaw puts enterprises at risk
Tags
 
 
 
Top Stories
Microsoft confirms Australian Azure launch
Available from next week.
 
NBN Co names first 140 FTTN sites
National trial extended.
 
Cloud, big data propel bank CISOs into the boardroom
And this time, they are welcome.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  25%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  22%
 
End user computing (desktops, mobiles, apps)
  14%
 
Software development
  27%
TOTAL VOTES: 260

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  62%
 
No
  38%
TOTAL VOTES: 82

Vote