[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [lemonade] Security Considerations Pawn Ticket URLs



Arnt,

Access to the media server is via SIP, which already has has mechanisms to restrict access to authorized users, such as by requesting authentication. For example, media servers might allow unauthenticated access from clients in the same administrative domain, but request credentials (or deny access) from clients in a different administrative domain.

In my opinion, the above mechanisms (policies for which would be in place regardless of streaming) would be enough to make such attacks as you describe below extremely difficult/unlikely. Media servers are extremely unlikely to allow access to the resources from any old network, and if they did, they probably wouldn't qualify to be included in the list of trusted servers. However, I think the possibility of this type of attack should be mentioned in the Security Considerations section.

Neil

On 24 Sep 2008, at 13:35, Arnt Gulbrandsen wrote:

Neil Cook writes:
The concern is about trust in the media server, i.e. that the client is passing a URI to a media server that may or may not be trusted to do the right thing with the content. What this proposes is a way to restrict the URL from being used by media servers that are not trusted by the IMAP server.

An untrusted malevolent media server can use the data if it can guess the name of an a trusted media server.

An innocent end user requests stream from an untrusted media server, which turns around, guesses a trusted server, connects to it, forwards the request and the stream and does something evil while forwarding.

This attack breaks down if either a) media servers tend to be secure against MITM attacks or b) guessing the name of the trusted media server is really difficult.

I guess I'm for or against the change depending on whether this attack works or not.

Arnt

_______________________________________________
lemonade mailing list
lemonade at ietf.org
https://www.ietf.org/mailman/listinfo/lemonade
Supplemental Web Site:
http://www.standardstrack.com/ietf/lemonade