[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: Exploiting XML namespaces formatted as IRIs (International

  • From: "G. Ken Holman" <gkholman@CraneSoftwrights.com>
  • To: "xml-dev@lists.xml.org" <xml-dev@lists.xml.org>
  • Date: Fri, 09 Dec 2011 12:12:26 -0500

Re:  Exploiting XML namespaces formatted as IRIs (International
At 2011-12-09 16:24 +0000, Costello, Roger L. wrote:
>Hi Folks,
>
>The namespaces in XML 1.1 can be any IRI 
>(Internationalized Resource Identifier) [1]
>
>Oftentimes namespaces are used in a dual role, 
>as a label for an XML vocabulary and as an 
>actual URL that one can dereference to get further information.
>
>Namespaces formatted as IRIs opens up the 
>possibility for a new type of attack: an IDN homograph attack [2].
>
>The internationalized domain name (IDN) 
>homograph attack is a way a malicious party may 
>deceive users about what remote system they are 
>communicating with, by exploiting the fact that 
>many different characters look alike, (i.e., 
>they are homographs, hence the term for the 
>attack). For example, consider an XML document 
>with the namespace http://www.citibank.com
>
><Document xmlns=" http://www.citibank.com">
>      ...
></Document>
>
>where the Latin C is replaced with the Cyrillic 
>รณ. A user of the XML document may dereference 
>the namespace URL and end up at a web site that 
>looks like Citibank but isn't. If the user were 
>to enter their username and password then their 
>information would go into the wrong hands.
>
>How can this attack be prevented?

If they received a document with a bogus 
namespace IRI, none of their namespace-aware XML 
processing would be successful and they would 
know right away that there is a problem.

While I've seen an XHTML page (typically with 
RDDL attributes) at the URL of the namespace URI, 
I've not seen any site that would require 
credentials to get access to namespace-related 
information.  That would be another red flag to me that something is amiss.

I would not be very worried about the scenario you present.

. . . . . . . . . . Ken


--
Contact us for world-wide XML consulting and instructor-led training
Free 5-hour video lecture: XSLT/XPath 1.0 & 2.0 http://ude.my/t37DVX
Crane Softwrights Ltd.            http://www.CraneSoftwrights.com/x/
G. Ken Holman                   mailto:gkholman@CraneSoftwrights.com
Google+ profile: https://plus.google.com/116832879756988317389/about
Legal business disclaimers:    http://www.CraneSoftwrights.com/legal



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.