Most popular file hosting sites ridden with security flaws
May 8, 2011
Internet security experts say they've discovered numerous security flaws in most of the popular file hosting sites that allow people to gain unauthorized access to data that's supposed to be available only to those selected by the user.
The Internet security experts include Nick Nikiforakis, Steven Van Acker, Wouter Joosen, of the Katholieke Université de Leuven in Belgium, then Marco Balduzzi and Davide Balzarotti of the Institute Eurecom in France.
Those file hosting services, which include sites such as RapidShare, FileFactory and EasyShare, allow users to upload large files and make them available to anyone who knows the unique URI (Uniform Resource Identifier) that's bound to each one.
Internet users can post the link on websites, in emails or on forums available to the public. For example, RapidShare says it can be used to share your data with your friends, colleagues or family.
But according to research academics in Belgium and France, a significant percentage of the 100 FHSs (File Hosting Services) they've studied made it very easy for outsiders to access the files simply by guessing the URLs that are bound to each uploaded file.
Making an already bad situation even worse, they presented more evidence that such Internet attacks, far from being theoretical, are already happening in the wild, and with increased frequency.
The academic researchers said they developed some software and then 'trained' web crawlers on the file services and uncovered hundreds of thousands of private files in just two weeks. They also used the file hosting sites to store private files that contained Internet beacons, so they'd know if anyone opened them. Over a month's span, no less than 80 unique IP addresses accessed the so-called "honey files" 275 times, indicating that the weakness is already being exploited in the wild to harvest data many users believe isn't available for general viewing or utilization.
“These so-called file hosting services adopt a security-through-obscurity mechanism where a user can access the uploaded files only by knowing the correct download URIs,” the researchers wrote in a paper presented at the most recent USENIX Workshop on Large-Scale Exploits and Emergent Threats.
“While these services claim that these URIs are secret and cannot be guessed, our study shows that this is far from being true,” said the researchers.
The security flaws that were the easiest to exploit were found on hosting sites that use sequential identifiers in the download URIs. By writing scripts that enumerate the IDs character by character, their bot crawler was able to locate almost 311,000 unique files over a period of just 30 days. The researchers then ran searches on Microsoft's Bing.com search engine to arrive at an estimate of 168,320 or 54 percent of them, were private files because they hadn't been shared online, at least not yet.
“Unfortunately, the security issues are extremely serious since the list of insecure FHSs using sequential IDs also include some of the most popular names, often highly ranked by Alexa in the list of the top Internet websites,” the researchers wrote.
But in an effort to prevent their findings from being abused, their report didn't say which specific sites are the most vulnerable to various types of attacks.
Get the best Linux or Windows Web hosting plan for your website.
Another common security flaw involved the use of pseudorandom URIs for each uploaded file. By using brute-force attacks that cycled through every possible known combination, the researchers were able to successfully guess a file's unique ID 1.1 times for every thousand attempts. Part of the weakness is the result of websites that used IDs that consisted of only numeric strings with a maximum length of six numbers. But even when services used IDs with alphanumeric characters or numbers with a length of 8, the researchers achieved similar success at penetration rates.
In other instances, some file hosting services used ID systems with enough complexity that rendered brute-force techniques ineffective or used CAPTCHAs (user-graphic input identifier boxes) or other mitigations.
However, and in many cases, the researchers were often able to guess the names anyway by simply exploiting a directory traversal vulnerability in a commonly-used web hosting program used by most file sharing services.
In other examples, they defeated the mitigation mechanism by using a feature that allows users to report copyright violations and other abuse to the site admins and combining it with a separate feature for deleting files. Because the feature on one site exposed the first 10 characters of a file's 14-character ID, the number of combinations to brute force was a manageable 65,536.
The security researchers said the most effective countermeasure against such attacks is the use of encryption technology on the user's computer. They developed a proof-of-concept Firefox add-on that automatically encrypts and decrypts files upon upload and download and uses steganographic (the art and science of writing hidden messages) techniques to hide the encrypted files.
Source: Université de Leuven, Belgium.
You can link to the Internet Security web site as much as you like.