{"id":229915,"date":"2017-09-20T09:14:34","date_gmt":"2017-09-20T07:14:34","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=229915"},"modified":"2017-09-20T09:14:34","modified_gmt":"2017-09-20T07:14:34","slug":"ropemaker-email-security-weakness-vulnerability-or-application-misuse","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/industrynews\/229915-ropemaker-email-security-weakness-vulnerability-or-application-misuse.html","title":{"rendered":"ROPEMAKER email security weakness &#8211; Vulnerability or application misuse?"},"content":{"rendered":"<p>Most people live under the assumption that email is immutable once delivered, like a physical letter.\u00a0 A new email exploit, dubbed ROPEMAKER by Mimecast\u2019s research team, turns that assumption on its head, undermining the security and non-repudiation of email; even for those that use SMIME or PGP for signing.\u00a0 Using the ROPEMAKER exploit a malicious actor can change the displayed content in an email at will. For example, a malicious actor could swap a benign URL with a malicious one in an email already delivered to your inbox, turn simple text into a malicious URL, or edit any text in the body of an email whenever they want. All of this can be done without direct access to the inbox.<\/p>\n<p>Described in more detail in a recently published\u00a0<a href=\"https:\/\/goo.gl\/ke7PVi\" data-saferedirecturl=\"https:\/\/www.google.com\/url?hl=en-GB&amp;q=https:\/\/goo.gl\/ke7PVi&amp;source=gmail&amp;ust=1505974153292000&amp;usg=AFQjCNGED2PL7Xb4Ztv67Gu2HQQIk4tDQg\">security advisory<\/a>, Mimecast has been able to add a defense against this exploit for our customers and also provide security recommendations that can be considered by non-customers to safeguard their email from this email exploit.<\/p>\n<p>So what is ROPEMAKER?<\/p>\n<p>The origin of ROPEMAKER lies at the intersection of email and Web technologies, more specifically Cascading Style Sheets (CSS) used with HTML.\u00a0 While the use of these Web technologies has made email more visually attractive and dynamic relative to its purely text-based predecessor, this has also introduced an exploitable\u00a0<a href=\"https:\/\/goo.gl\/dG9jhD\" data-saferedirecturl=\"https:\/\/www.google.com\/url?hl=en-GB&amp;q=https:\/\/goo.gl\/dG9jhD&amp;source=gmail&amp;ust=1505974153293000&amp;usg=AFQjCNEZdWimhwt7jsm4y3nWQ9kgebkPZw\">attack vector for email<\/a>.<\/p>\n<p>Clearly, giving attackers remote control over any aspect of ones\u2019 applications or infrastructure is a bad thing.\u00a0 As is described in more depth in the\u00a0<a href=\"https:\/\/goo.gl\/ke7PVi\" data-saferedirecturl=\"https:\/\/www.google.com\/url?hl=en-GB&amp;q=https:\/\/goo.gl\/ke7PVi&amp;source=gmail&amp;ust=1505974153293000&amp;usg=AFQjCNG5Sr2H7LOEhvId7zjWWF6ao_umLw\">ROPEMAKER Security Advisory<\/a>, this remote-control-ability could enable bad actors to direct unwitting users to malicious Web sites or cause other harmful consequences using a technique that could bypass common security controls and fool even the most security savvy users.\u00a0 ROPEMAKER could be leveraged in ways that are limited only by the creativity of the threat actors, which experience tells us, is often unlimited.<\/p>\n<p><strong>Changing this:<\/strong><\/p>\n<p><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-before.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-229923\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-before.jpg\" alt=\"\" width=\"640\" height=\"430\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-before.jpg 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-before-300x202.jpg 300w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-before-595x400.jpg 595w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><strong>Into this, post-delivery (without having direct access to the user\u2019s desktop):<\/strong><\/p>\n<p><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-after.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-229921\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-after.jpg\" alt=\"\" width=\"640\" height=\"430\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-after.jpg 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-after-300x202.jpg 300w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/09\/Ropemaker-after-595x400.jpg 595w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>To date, Mimecast has not seen ROPEMAKER exploited in the wild.\u00a0 We have, however, shown it to work on most popular email clients and online email services.\u00a0 Given that Mimecast currently serves more than 27K organizations and relays billions of emails monthly, if these types of exploits were being widely used it is very likely that Mimecast would see them.\u00a0 However, this is no guarantee that cybercriminals aren\u2019t currently taking advantage of ROPEMAKER in very\u00a0<a href=\"https:\/\/goo.gl\/xDzFRK\" data-saferedirecturl=\"https:\/\/www.google.com\/url?hl=en-GB&amp;q=https:\/\/goo.gl\/xDzFRK&amp;source=gmail&amp;ust=1505974153293000&amp;usg=AFQjCNHgJM7D6iHnN7KQiGHlgITPjchmug\">targeted attacks<\/a>.<\/p>\n<p>For details on email clients that we tested that are and are not exploitable by ROPEMAKER and the specifics on a security setting recommended by Apple for Apple Mail, please see the ROPEMAKER Security Advisory.<\/p>\n<p>Is ROPEMAKER a software vulnerability, a form of potential application abuse\/exploit, or a fundamental design flaw resulting from the intersection of Web technologies and email?\u00a0 Does it really matter which it is? For sure attackers don\u2019t care why a system can be exploited, only that it can be.<\/p>\n<p>If you agree that the potential of an email being changeable post-delivery under the control of a malicious actor increases the probability of a successful email-borne attack, the issue simplifies itself.\u00a0 Experience tells us that cybercriminals are always looking for the next email attack technique to use.\u00a0 As an industry let\u2019s work together to reduce the likelihood that the ROPEMAKER style of exploits gains any traction with cybercriminals!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Is ROPEMAKER a software vulnerability, a form of potential application abuse\/exploit, or a fundamental design flaw resulting from the intersection of Web technologies and email? Does it matter?<\/p>\n","protected":false},"author":341030,"featured_media":229919,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28937],"tags":[35,12213,37931],"class_list":["post-229915","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industrynews","tag-headline","tag-mimecast","tag-mimecast-south-africa"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/229915"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341030"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=229915"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/229915\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/229919"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=229915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=229915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=229915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}