1205 lines
71 KiB
HTML
1205 lines
71 KiB
HTML
<!doctype html>
|
||
<html>
|
||
<head>
|
||
<meta name="theme-color" content="#ffffff">
|
||
<meta charset="utf-8">
|
||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||
<link rel="stylesheet" href="/css/main.css">
|
||
<link rel="stylesheet" href="/css/prism.css">
|
||
<meta property="og:title" content="Cache Poisoned Denial of Service">
|
||
<meta property="og:image" content="https://cpdos.org/img/logo_2.png">
|
||
<meta name="description" content="A web attack which disables web resources">
|
||
<meta property="og:description" content="A web attack which disables web resources">
|
||
<title>CPDoS: Cache Poisoned Denial of Service</title>
|
||
</head>
|
||
<body data-spy="scroll" data-target="#navbar" data-offset="50">
|
||
<nav class="navbar navbar-default navbar-fixed-top">
|
||
<div class="container-fluid">
|
||
<div class="navbar-header">
|
||
<a class="navbar-brand text-right" href="/">CPDoS</a>
|
||
<button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#navbar" aria-expanded="false" aria-controls="navbar">
|
||
<span class="sr-only">Toggle navigation</span>
|
||
<span class="icon-bar"></span>
|
||
<span class="icon-bar"></span>
|
||
<span class="icon-bar"></span>
|
||
</button>
|
||
</div>
|
||
<div id="navbar" class="navbar-collapse collapse">
|
||
|
||
<ul class="nav navbar-nav">
|
||
<li role="presenation" class="dropdown"><a href="#attacks" class="dropdown-toggle" data-toggle="dropdown" aria-haspopup="true" aria-expanded="false"><span class="glyphicon glyphicon-fire" aria-hidden="true"> </span> Attacks <span class="caret"></span></a>
|
||
<ul class="dropdown-menu">
|
||
<li><a href="#HHO"></span>HTTP Header Oversize (HHO)</a></li>
|
||
<li><a href="#HMC">HTTP Meta Character (HMC)</a></li>
|
||
<li><a href="#HMO">HTTP Method Override (HMO)</a></li>
|
||
</ul>
|
||
</li>
|
||
|
||
<li><a href="#cpdos-spread"><span class="glyphicon glyphicon-globe" aria-hidden="true"></span> Impact</a></li>
|
||
<li><a href="#overview"><span class="glyphicon glyphicon-list-alt"></span> Vulnerability Overview</a></li>
|
||
<li><a href="#mitigations"><span class="glyphicon glyphicon-lock" aria-hidden="true"></span> Mitigations</a></li>
|
||
<li><a href="#paper"><span class="glyphicon glyphicon-education"></span> Paper/Talks</a></li>
|
||
<li><a href="#related_work"><span class="glyphicon glyphicon-book"></span> Related Work</a></li>
|
||
<li><a href="#coverage"><span class="glyphicon glyphicon-blackboard"></span> Coverage</a></li>
|
||
<li><a href="#vendor-responses-to-cpdos"><span class="glyphicon glyphicon-comment"></span> Vendor Responses</a></li>
|
||
<li><a href="#contact"> <span class="glyphicon glyphicon-envelope"></span> Contact</a></li>
|
||
</ul>
|
||
</div><!--/.nav-collapse -->
|
||
</div>
|
||
</nav>
|
||
<div class="jumbotron">
|
||
<div class="container page-header">
|
||
<img src="/img/logo_2.png" width="800" style="display:block; margin: auto;" class="img-responsive" alt="" />
|
||
<h1 class="text-center" id="cpdos-title"><strong>CPDoS</strong>: <br class="visible-xs" /> <strong>C</strong>ache <strong>P</strong>oisoned <strong>D</strong>enial <strong>o</strong>f <strong>S</strong>ervice</h1>
|
||
<!-- <p class="lead">Beat the security with their own weapons</p> -->
|
||
<!-- <h2>Read the Paper: <a href="/paper/Your_Cache_Has_Fallen__Cache_Poisoned_Denial_of_Service_Attack__Preprint_.pdf" class="btn btn-primary">Paper</a></h2> -->
|
||
</div>
|
||
</div>
|
||
<div class="container start main">
|
||
|
||
|
||
|
||
<h1 id="what-is-cpdos">What is CPDoS?</h1>
|
||
|
||
<p><strong>C</strong>ache-<strong>P</strong>oisoned <strong>D</strong>enial-<strong>o</strong>f-<strong>S</strong>ervice (<strong>CPDoS</strong>) is a new class of <a href="https://portswigger.net/research/practical-web-cache-poisoning" target="_blank">web cache poisoning attacks </a>aimed at disabling web resources and websites.</p>
|
||
<hr />
|
||
|
||
<h1 id="how-does-it-work">How does it work?</h1>
|
||
|
||
<p>The basic attack flow is described below and depicted in the following figure:</p>
|
||
|
||
<ol class="cpdos-list">
|
||
<li>
|
||
<p>An attacker sends a simple HTTP request containing a <strong>malicious header</strong> targeting a victim resource provided by some web server. The request is processed by the intermediate cache, while the malicious header remains unobtrusive.</p>
|
||
</li>
|
||
|
||
<li>
|
||
<p>The cache forwards the request to the origin server as it does not store a fresh copy of the targeted resource. At the origin server, the request processing provokes an <strong>error</strong> due to the malicious header it contains.</p>
|
||
</li>
|
||
|
||
<li>
|
||
<p>As a consequence, the origin server returns an <strong>error page</strong> which gets stored by the cache instead of the requested resource.</p>
|
||
</li>
|
||
|
||
<li>
|
||
<p>The attacker knows that the attack was successful when she retrieved an error page in response.</p>
|
||
</li>
|
||
|
||
<li> <p>Legitimate users trying to obtain the target resource with subsequent requests...</p> </li>
|
||
|
||
<li> <p>...will get the cached error page instead of the original content.</p></li>
|
||
</ol>
|
||
|
||
<p><img src="/img/CPDoS.png" alt="" class="img-thumbnail figure" /></p>
|
||
|
||
<p>With CPDoS, a malicious client can block <a href="#" data-toggle="popover" data-placement="top" data-content="Thus, the attacker can disable, e.g, vital web resources such as security updates, javascript files, or even the whole website for every client trying to access these ressources.">any web resource<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a> that is distributed via <a href="#" data-toggle="popover" data-placement="top" data-content="e.g., Cloudfront or Cloudflare">Content Distribution Networks (CDNs)<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a> or hosted on <a href="#" data-toggle="popover" data-placement="top" data-content="e.g., Varnish or Squid">proxy caches<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a>. Note, that <strong>a single crafted request</strong> is sufficient to restrain all subsequent requests from accessing the targeted content.</p>
|
||
|
||
<hr />
|
||
|
||
<h1 id="attacks">Which CPDoS variations exist?</h1>
|
||
<p>We detected three variations of CPDoS:</p>
|
||
|
||
<ul>
|
||
<li>
|
||
<p><a href="#HHO">HTTP Header Oversize (HHO)</a></p>
|
||
</li>
|
||
<li>
|
||
<p><a href="#HMC">HTTP Meta Character (HMC)</a></p>
|
||
</li>
|
||
<li>
|
||
<p><a href="#HMO">HTTP Method Override (HMO)</a></p>
|
||
</li>
|
||
</ul>
|
||
|
||
|
||
</div>
|
||
|
||
<div class="container main">
|
||
|
||
|
||
<h2 id="HHO">HTTP Header Oversize (HHO)</h2>
|
||
|
||
<p>An HTTP request header contains vital information for intermediate systems and web servers. This includes cache-related header fields or meta data on client supported media types, languages and encodings. The <a href="https://httpwg.org/specs/" target="_blank">HTTP standard</a> does not define any size limit for HTTP request headers. As a consequence, intermediate systems, web servers, and web frameworks define limits by their own. Most web servers and proxies such as <a href="https://httpd.apache.org/" target="_blank">Apache HTTPD</a> provide a request header size limit of around 8,192 bytes to mitigate, e.g., <a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2730" target="_blank">Request Header Buffer Overflow</a> or <a href="https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-staicu.pdf" target="_blank">ReDoS</a> attacks. However, there are also intermediate systems that specify limits larger than 8,192 bytes. For instance, the <a href="https://aws.amazon.com/cloudfront/" target="_blank">Amazon Cloudfront CDN</a> allows up to 20,480 bytes. This semantic gap in terms of request header size limits can be exploited to conduct a cache poisoning attack which can lead to a denial of service.
|
||
</p>
|
||
|
||
<p>HHO CPDoS attacks work in scenarios where a web application uses a cache that accepts a larger header size limit than the origin server. To attack such a web application, a malicious client sends a <code>HTTP GET</code> request including a header larger than the size supported by the origin server but smaller than the size supported by the cache. To do so, an attacker has two options. First, she crafts a request header with many malicious headers as shown in the following Ruby code snippet. The other option is to include one single header with an oversized key or value.</p>
|
||
|
||
<pre>
|
||
<code class="language-ruby">require 'net/http'
|
||
uri = URI("https://example.org/index.html")
|
||
req = Net::HTTP::Get.new(uri)
|
||
|
||
num = 200
|
||
i = 0
|
||
|
||
# Setting malicious and irrelevant headers fields for creating an oversized header
|
||
until i > num do
|
||
req["X-Oversized-Header-#{i}"] = "Big-Value-0000000000000000000000000000000000"
|
||
i +=1;
|
||
end
|
||
|
||
res = Net::HTTP.start(uri.hostname, uri.port, :use_ssl => uri.scheme == 'https') {|http|
|
||
http.request(req)
|
||
}</code>
|
||
</pre>
|
||
|
||
<p>The figure below shows an HHO CPDoS attack flow in which a malicious client sends a request created by the above code snippet. The cache forwards this request including all headers to the endpoint since the header size remains below the size limit of 20,480 bytes. The web server, however, blocks this request and returns an error page, as the request header exceeds its header size limit. This error page with status code <code>400 Bad Request</code> is now stored by the cache. All subsequent requests targeting the denialed resource are now provided with an error page instead of the genuine content.</p>
|
||
|
||
<p><img src="/img/HHO.png" alt="HRS attack" class="img-thumbnail figure" /></p>
|
||
|
||
<p>The video demonstrates the HHO CPDoS attack with an example web application hosted on Cloudfront. In the attack, embedded web resources are selectively replaced by error pages rendering first some parts of the web page and finally the entire page unavailable.</p>
|
||
|
||
<video width="100%" controls="">
|
||
<source src="/videos/HHO.mp4" type="video/mp4" />
|
||
</video>
|
||
|
||
|
||
<hr />
|
||
|
||
|
||
<h2 id="HMC">HTTP Meta Character (HMC)</h2>
|
||
|
||
<p>The HTTP Meta Character (HMC) CPDoS attack works similar to the HHO CPDoS attack. Instead of sending an oversized header, this attack tries to bypass a cache with a request header containing a harmful meta character. Meta characters can be, e.g., control characters such as line break/carriage return (<code>\n</code>), line feed (<code>\r</code>) or bell (<code>\a</code>).</p>
|
||
|
||
<p><img src="/img/HMC.png" alt="" class="img-thumbnail figure" /></p>
|
||
|
||
<p>An unaware cache forwards such a request to the origin server without blocking the message or sanitizing the meta characters. The origin server, however, may classify such a request as malicious as it contains harmful meta characters. As a consequence, the origin server returns an error message which is stored and reused by the cache.</p>
|
||
|
||
|
||
<hr />
|
||
|
||
|
||
<h2 id="HMO">HTTP Method Override Attack (HMO)</h2>
|
||
|
||
<p>The <a href="https://httpwg.org/specs/" target="_blank">HTTP standard</a> provides several HTTP methods for web servers and clients for performing transactions on the web. <code>GET</code>, <code>POST</code>, <code>DELETE</code> and <code>PUT</code> are arguably the most used HTTP methods in web applications and REST-based web services. Many intermediate systems such as proxies, load balancers, caches, and firewalls, however, do only support <code>GET</code> and <code>POST</code>.
|
||
This means that HTTP requests with <code>DELETE</code> and <code>PUT</code> are simply blocked. To circumvent this restriction many REST-based APIs or web frameworks such as the <a href="https://www.playframework.com/documentation/1.5.x/home" target="_blank">Play Framework 1</a>, provide headers such as <code>X-HTTP-Method-Override</code>, <code>X-HTTP-Method</code> or <code>X-Method-Override</code> for tunnel blocked HTTP methods. Once the request reaches the server, the header instructs the web application to override the HTTP method in the request line with the one in the corresponding header value.</p>
|
||
|
||
<div class="row">
|
||
<div class="col-md-12">
|
||
<pre>
|
||
<code class="">POST /items/1 HTTP/1.1
|
||
Host: example.org
|
||
<strong>X-HTTP-Method-Override: DELETE</strong>
|
||
|
||
HTTP/1.1 200 OK
|
||
Content-Type: text/plain
|
||
Content-Length: 62
|
||
|
||
Resource has been successfully removed with the DELETE method.
|
||
</code>
|
||
</pre>
|
||
</div>
|
||
</div>
|
||
|
||
<p>The code snippet shows a request that can bypass a security policy that prohibits <code>DELETE</code> requests by using the <code>X-HTTP-Method-Override</code> header. On the server-side this <code>POST</code> request will be interpreted as a <code>DELETE</code> request.</p>
|
||
|
||
<p>These method overriding headers are very useful in scenarios when intermediate systems block distinct HTTP methods.
|
||
However, if a web application supports such a header and also uses a web caching system like a reverse proxy cache or CDN for optimizing performance, a malicious client can exploit this constellation to conduct a CPDoS attack. The figure below illustrates the principle flow of an HTTP Method Override Attack (HMO) CPDoS attack using the <code>X-HTTP-Method-Override</code> header.</p>
|
||
|
||
<p><img src="/img/HMO.png" alt="HRS attack" class="img-thumbnail figure" /></p>
|
||
|
||
<p>Here, the attacker sends a <code>GET</code> request with an <code>X-HTTP-Method-Override</code> header containing <code>POST</code>. A vulnerable cache interprets this request as a benign <code>GET</code> request targeting the resource <ins>https://example.org/index.html</ins>. The web application, however, will interpret this request as a <code>POST</code> request, since the <code>X-HTTP-Method-Override</code> header instructs the server to replace the HTTP method in the request line. Accordingly, the web application returns a response based on <code>POST</code>. Let’s assume that the target web application doesn’t implement any business logic for <code>POST</code> on <ins>/index.html</ins>. In such cases, web frameworks like the <a href="https://www.playframework.com/documentation/1.5.x/home" target="_blank">Play Framework 1</a> return an error message with the status code <code>404 Not Found</code>. The cache assumes that the returned response with the error code is the result of the <code>GET</code> request targeting <ins>https://example.org/index.html</ins>. Since the status code <code>404 Not Found</code> is allowed to be cached according to the <a href="https://tools.ietf.org/html/rfc7231" target="_blank">HTTP Caching RFC 7231</a>, caches store and reuse this error response for recurring requests.
|
||
Each benign client making a subsequent <code>GET</code> request to <ins>https://example.org/index.html</ins> will receive a stored error message with status code <code>404 Not Found</code> instead of the genuine web application’s start page.</p>
|
||
|
||
<p>The video below demonstrates an HMO attack on a web application. Here, the attacker uses the <a href="https://www.getpostman.com/downloads/" target="_blank">Postman</a> tool to block the start page from being accessed.</p>
|
||
<video width="100%" controls="">
|
||
<source src="/videos/HMO.mp4" type="video/mp4" />
|
||
</video>
|
||
|
||
|
||
<hr />
|
||
|
||
|
||
<h1 id="cpdos-spread">Impact</h1>
|
||
|
||
<p>The map below shows the impact of CPDoS attacks on CDNs. Once the error page is injected, the CDN distributes it to many other edge cache server locations around the world. The map illustrates how far the error page is distributed to several edge locations within the CDN. The <img src="/img/red-pin.png" width="12.5" alt="" /> icons show the affected locations displaying the error page. Fortunately, not all edge servers are infected by this attack which is shown by the <img src="/img/green-pin.png" width="12.5" alt="" /> icons. This icon denotes the locations where clients receive the genuine page. The <img width="12.5" src="/img/blue-pin.png" /> icon shows the location of the origin server and the <img width="12.5" src="/img/attacker.png" /> icon displays the attacker’s locations.</p>
|
||
|
||
<p>The first figure shows the affected regions in Europe and some parts of Asia when sending a CPDoS attack from Frankfurt, Germany to a victim origin server in Cologne, Germany. The second one illustrates the poisoned regions in the USA when executing a CPDoS attack from Northern Virginia, USA to the same victim origin server in Cologne, Germany.
|
||
<img src="/img/affected_regions_europe_cut.png" class="img-thumbnail figure" /></p>
|
||
|
||
<p><img src="/img/affected_regions_usa_cut.png" class="img-thumbnail figure" />
|
||
<br /></p>
|
||
|
||
<p>This analysis has been conducted with <a href="https://pulse.turbobytes.com/" target="_blank">TurboBytes Pulse</a> and <a href="https://tools.keycdn.com/speed" target="_blank">the speed testing tool of KeyCDN</a>. Both services provide a testing environment covering a lot of test agents scattered around the world.</p>
|
||
|
||
|
||
<hr />
|
||
<h1 id="overview">CPDoS vulnerability overview</h1>
|
||
|
||
<p>This overview summarizes what pair of web caching system and HTTP implementation is vulnerable to what CPDoS attack. More details are described in the paper which can be downloaded <a href="#paper">below</a>.
|
||
<strong>Note, that the table below illustrates the results from our research experiments conducted in February 2019. In the meantime, the affected organizations have taken precautions to mitigate CPDoS attacks. The majority of the CPDoS vulnerabilities has been addressed by the respective organizations. Click on the info icons in the table or see the section <a href="#vendor-responses-to-cpdos">Vendor Responses to CPDoS</a> for more details.</strong>
|
||
|
||
</p>
|
||
|
||
<div style="overflow: auto">
|
||
<table class="table table-bordered table-striped cpdos-overview">
|
||
|
||
<tr>
|
||
<th class="diag"><span class="leftbottom">HTTP Implementation</span><span class="topright">Cache</span></th>
|
||
<th>Apache HTTPD</th>
|
||
<th>Apache TS</th>
|
||
<th>Nginx</th>
|
||
<th>Squid</th>
|
||
<th>Varnish</th>
|
||
<th>Akamai</th>
|
||
<th>Azure</th>
|
||
<th>CDN77</th>
|
||
<th>CDNSun</th>
|
||
<th>Cloudflare</th>
|
||
<th colspan="1"><a href="#" data-toggle="popover" data-placement="top" data-content="Fixed (see <a href='https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/HTTPStatusCodes.html' target='_blank'>CloudFront documentation</a>)">CloudFront<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a></th>
|
||
<th>Fastly</th>
|
||
<th>G-Core Labs</th>
|
||
<th>KeyCDN</th>
|
||
<th>StackPath</th>
|
||
</tr>
|
||
<tr>
|
||
<td>Apache HTTPD + (ModSecurity)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO, HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Apache TS</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Nginx + (ModSecurity)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td><a href="#" data-toggle="popover" data-placement="top" data-content="Fixed (see <a href='https://portal.msrc.microsoft.com/de-DE/security-guidance/advisory/CVE-2019-0941' target='_blank'>CVE-2019-0941</a>)">IIS<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a></td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>(HHO)</td>
|
||
<td>(HHO)</td>
|
||
<td>○</td>
|
||
<td>(HHO)</td>
|
||
<td>○</td>
|
||
<td>(HHO)</td>
|
||
<td>HHO, HMC</td>
|
||
<td>(HHO)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Tomcat</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Squid</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Varnish</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO, HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Amazon S3</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Google Cloud Storage</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Github Pages</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO, HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Gitlab Pages</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Heroku</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td><!-- <a href="#" data-toggle="popover" data-placement="top" data-content="Potentially vulnerable to HHO when using with IIS as web server">ASP.NET<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a> --> ASP.NET</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>(HHO)</td>
|
||
<td>(HHO)</td>
|
||
<td>○</td>
|
||
<td>(HHO)</td>
|
||
<td>○</td>
|
||
<td>(HHO)</td>
|
||
<td>(HHO), (HMC)</td>
|
||
<td>(HHO)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>BeeGo</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Django</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>(HHO), (HMC)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Express.js</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Flask</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>(HMO)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HMO, (HHO), (HMC)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Gin</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Laravel</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>(HHO), (HMC)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Meteor.js</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td><a href="#" data-toggle="popover" data-placement="top" data-content="Fixed (see <a href='https://github.com/playframework/play1/issues/1300' target='_blank'>GitHub Play 1 issue 1300</a>)">Play 1<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a></td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HMO</td>
|
||
<td>HMO</td>
|
||
<td>○</td>
|
||
<td>HMO</td>
|
||
<td>○</td>
|
||
<td>HMO</td>
|
||
<td>HHO, HMO</td>
|
||
<td>HMO</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Play 2</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO, HMC</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Rails</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>(HHO), (HMC)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Spring Boot</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>HHO</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
<tr>
|
||
<td>Symfony</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>(HHO), (HMC)</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
<td>○</td>
|
||
</tr>
|
||
</table>
|
||
</div>
|
||
<hr />
|
||
|
||
|
||
<h1 id="mitigations">Mitigations</h1>
|
||
|
||
<p>One of the main reasons for HHO and HMC CPDoS attacks lies in the fact that a vulnerable cache illicitly stores responses containing error codes such as <code>400 Bad Request</code> by default. This is not allowed according to the HTTP standard. The web caching standard only allows to cache the error codes <code>404 Not Found</code>, <code>405 Method Not Allowed</code>, <code>410 Gone</code> and <code>501 Not Implemented</code>. Hence, caching error pages according to the policies of the HTTP standard is the first step to avoid CPDoS attacks.</p>
|
||
|
||
<p>Content providers must also use the appropriate status code for the corresponding error case. For instance, <code>400 Bad Request</code> which is used by many HTTP implementations for declaring an oversized header is not the suitable status code.
|
||
IIS even uses <code>404 Not Found</code> when a specific header is exceeded. The right error code for an oversized request header is <code>431 Request Header Fields Too Large</code>. According to our analysis, this error message is not cached by any web caching systems.</p>
|
||
|
||
<p>Another effective countermeasure against HHO and HMC CPDoS attacks is to exclude error pages from caching. One approach is to add the header <code>Cache-Control: no-store</code> to each error page. The other option is to disable error page caching in the cache configuration. CDNs like CloudFront or Akamai provide configuration settings to do so.</p>
|
||
|
||
<p>A Web Application Firewalls (WAF) can also be deployed to mitigate CPDoS attacks. However, WAFs must be placed in front of the cache in order to block malicious content before they reach the origin server. WAFs that are placed in front of the origin server can be exploited to provoke error pages that get cached either.</p>
|
||
|
||
<p>For more details on possible mitigations and countermeasures, please read our paper.</p>
|
||
|
||
|
||
<hr />
|
||
|
||
|
||
<h1 id="paper">Paper</h1>
|
||
<p>For more details on CPDoS attacks, you are welcome to read our research paper. A preprint can be downloaded below.</p>
|
||
|
||
<div class="panel panel-default">
|
||
<div class="panel-body">
|
||
<small><em>Hoai Viet Nguyen, Luigi Lo Iacono, and Hannes Federrath</em></small><br />
|
||
<strong>Your Cache Has Fallen: Cache-Poisoned Denial-of-Service Attack</strong><br />
|
||
<small>26th ACM Conference on Computer and Communications Security (CCS) 2019</small>
|
||
<br />
|
||
<div class="btn-group" role="group" aria-label="...">
|
||
<a class="btn btn-small btn-primary" data-toggle="collapse" href="#abstract" aria-expanded="false" aria-controls="abstract">Abstract
|
||
</a>
|
||
<a class="btn btn-small btn-primary" data-toggle="collapse" href="#bibtex" aria-expanded="false" aria-controls="bibtex">
|
||
Bibtex
|
||
</a>
|
||
<a class="btn btn-small btn-primary" href="/paper/Your_Cache_Has_Fallen__Cache_Poisoned_Denial_of_Service_Attack__Preprint_.pdf" target="_blank">Download</a>
|
||
</div>
|
||
<div id="abstract" class="collapse">
|
||
<div class="panel panel-default">
|
||
<div class="panel-body">
|
||
<h4>Abstract</h4>
|
||
<p>Web caching enables the reuse of HTTP responses with the aim to reduce the number of requests that reach the origin server, the volume of network traffic resulting from resource requests, and the user-perceived latency of resource access. For these reasons, a cache is a key component in modern distributed systems as it enables applications to scale at large. In addition to optimizing performance metrics, caches promote additional protection against Denial of Service (DoS) attacks.</p>
|
||
|
||
<p>In this paper we introduce and analyze a new class of web cache poisoning attacks. By provoking an error on the origin server that is not detected by the intermediate caching system, the cache gets poisoned with the server-generated error page and instrumented to serve this useless content instead of the intended one, rendering the victim service unavailable. In an extensive study of fifteen web caching solutions we analyzed the negative impact of the Cache-Poisoned DoS (CPDoS) attack---as we coined it. We show the practical relevance by identifying one proxy cache product and five CDN services that are vulnerable to CPDoS. Amongst them are prominent solutions that in turn cache high-value websites. The consequences are severe as one simple request is sufficient to paralyze a victim website within a large geographical region. The awareness of the newly introduced CPDoS attack is highly valuable for researchers for obtaining a comprehensive understanding of causes and countermeasures as well as practitioners for implementing robust and secure distributed systems.</p>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="collapse" id="bibtex">
|
||
<pre>
|
||
@inproceedings{conf/ccs2019/nguyen,
|
||
author = {H.V. Nguyen and L. Lo Iacono and H. Federrath},
|
||
title = {{Your Cache Has Fallen: Cache-Poisoned Denial-of-Service Attack}},
|
||
booktitle = {{26th ACM Conference on Computer and Communications Security (CCS)}},
|
||
year = {2019},
|
||
url = {https://doi.org/10.1145/3319535.3354215},
|
||
abstract = {{Web caching enables the reuse of HTTP responses with the aim to reduce the number of requests
|
||
that reach the origin server, the volume of network traffic resulting from resource requests, and the user-
|
||
perceived latency of resource access. For these reasons, a cache is a key component in modern distributed
|
||
systems as it enables applications to scale at large. In addition to optimizing performance metrics, caches
|
||
promote additional protection against Denial of Service (DoS) attacks.
|
||
|
||
In this paper we introduce and analyze a new class of web cache poisoning attacks. By provoking an error on
|
||
the origin server that is not detected by the intermediate caching system, the cache gets poisoned with the
|
||
server-generated error page and instrumented to serve this useless content instead of the intended one,
|
||
rendering the victim service unavailable. In an extensive study of fifteen web caching solutions we analyzed
|
||
the negative impact of the Cache-Poisoned DoS (CPDoS) attack---as we coined it. We show the practical
|
||
relevance by identifying one proxy cache product and five CDN services that are vulnerable to CPDoS. Amongst
|
||
them are prominent solutions that in turn cache high-value websites. The consequences are severe as one simple
|
||
request is sufficient to paralyze a victim website within a large geographical region. The awareness of the
|
||
newly introduced CPDoS attack is highly valuable for researchers for obtaining a comprehensive understanding
|
||
of causes and countermeasures as well as practitioners for implementing robust and secure distributed systems.
|
||
}}
|
||
}
|
||
</pre></div>
|
||
</div>
|
||
</div>
|
||
|
||
<hr />
|
||
|
||
<h1 id="talks">Talks</h1>
|
||
<p>On November 14th, 2019, we will give a talk on CPDoS attacks at the <a href="#" data-toggle="popover" data-placement="top" data-content="26th ACM Conference on Computer and Communications Security, November 11-15, 2019, London, UK.">CCS 2019<sup><span class="glyphicon glyphicon-info-sign" aria-hidden="true" data-html="true"></span></sup></a>. For more information, please take a look at the CCS’ agenda: <a target="_blank" href="https://sigsac.org/ccs/CCS2019/index.php/program/program-2/#Thursday">https://sigsac.org/ccs/CCS2019/…</a></p>
|
||
|
||
<hr />
|
||
<h1 id="related_work">Related Work</h1>
|
||
|
||
<p>HHO, HMC and HMO are not the only CPDoS variations. In March 2019, <a href="https://nathandavison.com/blog/corsing-a-denial-of-service-via-cache-poisoning" target="_blank">Nathan Davison</a> has detected a CPDoS variation which use CORS headers. Also, Nathan posted a blog post on using the Connection header to conduct a CPDoS attack.</p>
|
||
|
||
<p>Moreover, James Kettle has published a <a href="https://portswigger.net/research/responsible-denial-of-service-with-web-cache-poisoning" target="_blank">blog article</a> discussing other variations of CPDoS attacks on real world websites. James is Head of Research at PortSwigger Web Security. He wrote many blog articles on <a href="https://portswigger.net/research/practical-web-cache-poisoning" target="_blank">practical web cache poisoning vulnerabilities</a> as well as a new variation of HTTP Request Smuggling denoted as <a href="https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn" targe="_blank">HTTP Desync Attacks</a>.</p>
|
||
<hr />
|
||
|
||
|
||
<h1 id="coverage">Coverage</h1>
|
||
|
||
<p>www.hostingadvice.com<br />
|
||
<em>March 30, 2020</em><br />
|
||
<strong>Researchers Identify a New Cache Poisoning Attack Impacting CDNs That Could Block Web Resources and Sites</strong><br />
|
||
<a href="https://www.hostingadvice.com/blog/researchers-identify-new-cache-poisoning-attack/" target="_blank">https://www.hostingadvice.com/blog/researchers-identify-new-cache-poisoning-attack/</a></p>
|
||
|
||
<p>nathandavison.com<br />
|
||
<em>February 24, 2020</em><br />
|
||
<strong>Cache poisoning DoS in CloudFoundry gorouter (CVE-2020-5401)</strong><br />
|
||
<a href="https://nathandavison.com/blog/cache-poisoning-dos-in-cloudfoundry-gorouter" target="_blank">https://nathandavison.com/blog/cache-poisoning-dos-in-cloudfoundry-gorouter</a></p>
|
||
|
||
<p>Golem.de<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>Cache-Angriffe können Webseiten lahmlegen</strong><br />
|
||
<a href="https://www.golem.de/news/cpdos-angriff-cache-angriffe-koennen-webseiten-lahmlegen-1910-144575.html" target="_blank">https://www.golem.de/news/cpdos-angriff-cache-angriffe-koennen-webseiten-lahmlegen-1910-144575.html</a></p>
|
||
|
||
<p>The Hacker News<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>New Cache Poisoning Attack Lets Attackers Target CDN Protected Sites</strong><br />
|
||
<a href="https://thehackernews.com/2019/10/cdn-cache-poisoning-dos-attack.html" target="_blank">https://thehackernews.com/2019/10/cdn-cache-poisoning-dos-attack.html</a></p>
|
||
|
||
<p>ZDNet<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>CPDoS attack can poison CDNs to deliver error pages instead of legitimate sites</strong><br />
|
||
<a href="https://www.zdnet.com/article/cpdos-attack-can-poison-cdns-to-deliver-error-pages-instead-of-legitimate-sites/" target="_blank">https://www.zdnet.com/article/cpdos-attack-can-poison-cdns-to-deliver-error-pages-instead-of-legitimate-sites/</a></p>
|
||
|
||
<p>Bleeping Computer<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>New CPDoS Web Cache Poisoning Attacks Impact Sites Using Popular CDNs</strong><br />
|
||
<a href="https://www.bleepingcomputer.com/news/security/new-cpdos-web-cache-poisoning-attacks-impact-sites-using-popular-cdns/" target="_blank">https://www.bleepingcomputer.com/news/security/new-cpdos-web-cache-poisoning-attacks-impact-sites-using-popular-cdns/</a></p>
|
||
|
||
<p>Cyware<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>New ‘CPDoS’ Web Cache Poisoning Attack Impacts Content Delivery Networks (CDN)</strong><br />
|
||
<a href="https://cyware.com/news/new-cpdos-web-cache-poisoning-attack-impacts-content-delivery-networks-cdn-440ffccc/" target="_blank">https://cyware.com/news/new-cpdos-web-cache-poisoning-attack-impacts-content-delivery-networks-cdn-440ffccc/</a></p>
|
||
|
||
<p>Security Affairs<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>Exploring the CPDoS attack on CDNs: Cache Poisoned Denial of Service</strong><br />
|
||
<a href="https://securityaffairs.co/wordpress/92859/hacking/cpdos-attack-cdns.html" target="_blank">https://securityaffairs.co/wordpress/92859/hacking/cpdos-attack-cdns.html</a></p>
|
||
|
||
<p>The Media HQ<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>CPDoS attack can poison CDNs to deliver error pages instead of legitimate sites</strong><br />
|
||
<a href="https://themediahq.com/cpdos-attack-can-poison-cdns-to-deliver-error-pages-instead-of-legitimate-sites/" target="_blank">https://themediahq.com/cpdos-attack-can-poison-cdns-to-deliver-error-pages-instead-of-legitimate-sites/</a></p>
|
||
|
||
<p>Reblaze
|
||
<em>October 23, 2019</em><br />
|
||
<strong>CPDoS – A new DoS attack on the rise</strong><br />
|
||
<a href="https://www.reblaze.com/blog/cpdos-new-dos-attacks-rise/" target="_blank">https://www.reblaze.com/blog/cpdos-new-dos-attacks-rise/</a></p>
|
||
|
||
<p>SensorsTechForum<br />
|
||
<em>October 24, 2019</em><br />
|
||
<strong>Cache Poisoned Denial of Service (CPDoS) Attacks Used Against Content Delivery Networks</strong><br />
|
||
<a href="https://sensorstechforum.com/cpdos-attacks-cdn/" target="_blank">https://sensorstechforum.com/cpdos-attacks-cdn/</a></p>
|
||
|
||
<p>Naked Security<br />
|
||
<em>October 24, 2019</em><br />
|
||
<strong>Vulnerability in content distribution networks found by researchers</strong><br />
|
||
<a href="https://nakedsecurity.sophos.com/2019/10/24/researchers-find-vulnerability-in-content-distribution-networks/" target="_blank">https://nakedsecurity.sophos.com/2019/10/24/researchers-find-vulnerability-in-content-distribution-networks/</a></p>
|
||
|
||
<p>ACM TECHNEWS<br />
|
||
<em>October 24, 2019</em><br />
|
||
<strong>CPDoS Attack Can Poison CDNs to Deliver Error Pages Instead of Legitimate Sites</strong><br />
|
||
<a href="https://cacm.acm.org/news/240392-cpdos-attack-can-poison-cdns-to-deliver-error-pages-instead-of-legitimate-sites/fulltext" target="_blank">https://cacm.acm.org/news/240392-cpdos-attack-can-poison-cdns-to-deliver-error-pages-instead-of-legitimate-sites/fulltext</a></p>
|
||
|
||
<p>Security Week<br />
|
||
<em>October 24, 2019</em><br />
|
||
<strong>Researchers Warn of New Cache-Poisoned DoS Attack Method</strong><br />
|
||
<a href="https://www.securityweek.com/researchers-warn-new-cache-poisoned-dos-attack-method" target="_blank">https://www.securityweek.com/researchers-warn-new-cache-poisoned-dos-attack-method</a></p>
|
||
|
||
<p>Cybers Guard<br />
|
||
<em>October 25, 2019</em><br />
|
||
<strong>Experts Warn of the Latest Cache-Poisoned Method of Attack</strong><br />
|
||
<a href="https://cybersguards.com/experts-warn-of-the-latest-cache-poisoned-method-of-attack/" target="_blank">https://cybersguards.com/experts-warn-of-the-latest-cache-poisoned-method-of-attack/</a></p>
|
||
|
||
|
||
<hr />
|
||
|
||
|
||
<h1 id="vendor-responses-to-cpdos">Vendor Responses to CPDoS</h1>
|
||
|
||
<p>Play Framework<br />
|
||
<em>March 14, 2019</em><br />
|
||
<strong>Define allowed methods used in ‘X-HTTP-Method-Override’</strong><br />
|
||
<a href="https://github.com/playframework/play1/issues/1300" target="_blank">https://github.com/playframework/play1/issues/1300</a></p>
|
||
|
||
<p>Microsoft<br />
|
||
<em>June 11, 2019</em><br />
|
||
<strong>CVE-2019-0941 | Microsoft IIS Server Denial of Service Vulnerability</strong><br />
|
||
<a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941" target="_blank">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941</a></p>
|
||
|
||
<p>Amazon Web Services<br />
|
||
<em>September 7, 2019</em><br />
|
||
<strong>How CloudFront Processes and Caches HTTP 4xx and 5xx Status Codes from Your Origin</strong><br />
|
||
<a href="https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/HTTPStatusCodes.html" target="_blank">https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/HTTPStatusCodes.html</a></p>
|
||
|
||
<p>Akamai<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>CPDOS POISONING ATTACK</strong><br />
|
||
<a href="https://blogs.akamai.com/2019/10/cpdos-poisoning-attack.html" target="_blank">https://blogs.akamai.com/2019/10/cpdos-poisoning-attack.html</a></p>
|
||
|
||
<p>Cloudflare<br />
|
||
<em>October 24, 2019</em><br />
|
||
<strong>Cloudflare response to CPDoS exploits</strong><br />
|
||
<a href="https://blog.cloudflare.com/cloudflare-response-to-cpdos-exploits/" target="_blank">https://blog.cloudflare.com/cloudflare-response-to-cpdos-exploits/</a></p>
|
||
|
||
<p>CDN77<br />
|
||
<em>October 23, 2019</em><br />
|
||
<strong>Our statement regarding today’s article published by @TheHackersNews CDN77 is not vulnerable to CPDoS attacks.</strong>
|
||
<a href="https://twitter.com/CDN77com/status/1186971315217092612" target="_blank">https://twitter.com/CDN77com/status/1186971315217092612</a></p>
|
||
|
||
<p>Verizon Digital Media<br />
|
||
<em>October 28, 2019</em><br />
|
||
<strong>CPDoS attack update</strong><br />
|
||
<a href="https://www.verizondigitalmedia.com/blog/cpdos-attack-update/" target="_blank">https://www.verizondigitalmedia.com/blog/cpdos-attack-update/</a></p>
|
||
|
||
<hr />
|
||
|
||
|
||
<h1 id="contact">Contact</h1>
|
||
<div class="row">
|
||
<div class="col-sm-3 col-md-3">
|
||
<div class="thumbnail">
|
||
<img src="/img/viet.jpg" alt="..." />
|
||
<div class="caption">
|
||
<h3>Hoai Viet Nguyen</h3>
|
||
|
||
<p><a href="mailto:viet.nguyen@th-koeln.de" class="btn btn-primary" role="button"><span class="glyphicon glyphicon-envelope"></span></a> <a href="https://das.th-koeln.de" target="_blank" class="btn btn-default" role="button"><span class="glyphicon glyphicon-link"></span></a></p>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<div class="col-sm-3 col-md-3">
|
||
<div class="thumbnail">
|
||
<img src="/img/luigi.jpg" alt="..." />
|
||
<div class="caption">
|
||
<h3>Luigi Lo Iacono</h3>
|
||
|
||
<p><a href="mailto:luigi.lo_iacono@th-koeln.de" class="btn btn-primary" role="button"><span class="glyphicon glyphicon-envelope"></span></a> <a href="https://das.th-koeln.de" target="_blank" class="btn btn-default" role="button"><span class="glyphicon glyphicon-link"></span></a></p>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
|
||
|
||
</div>
|
||
<!-- Modal -->
|
||
<div class="modal fade" id="imprintModal" tabindex="-1" role="dialog" aria-labelledby="imprint">
|
||
<div class="modal-dialog modal-lg" role="document">
|
||
<div class="modal-content">
|
||
<div class="modal-header">
|
||
<button type="button" class="close" data-dismiss="modal" aria-label="Close"><span aria-hidden="true">×</span></button>
|
||
<h4 class="modal-title" id="myModalLabel">Imprint</h4>
|
||
</div>
|
||
<div class="modal-body">
|
||
<h1 id="legal-disclosure">Legal Disclosure</h1>
|
||
<p>Information in accordance with section 5 TMG</p>
|
||
<p>TH Köln - University of Applied Sciences<br /> F07/IMP<br /> Data and Application Security Group<br /> Gustav-Heinemann-Ufer 54<br /> 50968 Cologne</p>
|
||
<h2 id="represented-by">Represented by</h2>
|
||
<p>Prof. Dr. Luigi Lo Iacono</p>
|
||
<h2 id="contact">Contact</h2>
|
||
<p>Telephone: 0221/8275-2527<br /> E-Mail: luigi.lo_iacono at th-koeln.de<br /> Website: <a href="http://das.th-koeln.de" target="_blank">das.th-koeln.de</a></p>
|
||
<h2 id="person-responsible-for-content-in-accordance-with-55-abs-2-rstv">Person responsible for content in accordance with 55 Abs. 2 RStV</h2>
|
||
<ul>
|
||
<li>Hoai Viet Nguyen</li>
|
||
<li>Luigi Lo Iacono</li>
|
||
</ul>
|
||
<h2 id="indication-of-source-for-images-and-graphics">Indication of source for images and graphics</h2>
|
||
|
||
<p>Bomb, Recycle, and Server and icons made by <a href="https://www.flaticon.com/authors/freepik" title="Freepik">Freepik</a> from <a href="https://www.flaticon.com/" title="Flaticon">www.flaticon.com</a></p>
|
||
<p>404 icon made by <a href="https://www.flaticon.com/authors/dinosoftlabs" title="DinosoftLabs">DinosoftLabs</a> from <a href="https://www.flaticon.com/" title="Flaticon">www.flaticon.com</a></p>
|
||
<p>Cloud icon made by <a href="https://www.flaticon.com/authors/smashicons" title="Smashicons">Smashicons</a> from <a href="https://www.flaticon.com/" title="Flaticon">www.flaticon.com</a></p>
|
||
<p>Explosion icon made by <a href="https://www.flaticon.com/authors/good-ware" title="Good Ware">Good Ware</a> from <a href="https://www.flaticon.com/" title="Flaticon">www.flaticon.com</a></p>
|
||
|
||
<h2 id="disclaimer">Disclaimer</h2>
|
||
<p>Accountability for content<br /> The contents of our pages have been created with the utmost care. However, we cannot guarantee the contents’ accuracy, completeness or topicality. According to statutory provisions, we are furthermore responsible for our own content on these web pages. In this context, please note that we are accordingly not obliged to monitor merely the transmitted or saved information of third parties, or investigate circumstances pointing to illegal activity. Our obligations to remove or block the use of information under generally applicable laws remain unaffected by this as per §§ 8 to 10 of the Telemedia Act (TMG).</p>
|
||
<p>Accountability for links<br /> Responsibility for the content of external links (to web pages of third parties) lies solely with the operators of the linked pages. No violations were evident to us at the time of linking. Should any legal infringement become known to us, we will remove the respective link immediately.</p>
|
||
<p>Copyright<br /> Our web pages and their contents are subject to German copyright law. Unless expressly permitted by law (§ 44a et seq. of the copyright law), every form of utilizing, reproducing or processing works subject to copyright protection on our web pages requires the prior consent of the respective owner of the rights. Individual reproductions of a work are allowed only for private use, so must not serve either directly or indirectly for earnings. Unauthorized utilization of copyrighted works is punishable (§ 106 of the copyright law).</p>
|
||
<hr />
|
||
<h1 id="datenschutzerklärung">Datenschutzerklärung</h1>
|
||
<ul>
|
||
<li><a href="#a.-name-und-anschrift-des-verantwortlichen">A. Name und Anschrift des Verantwortlichen</a></li>
|
||
<li><a href="#b.-name-und-anschrift-der-datenschutzbeauftragten-der-th-köln">B. Name und Anschrift der Datenschutzbeauftragten der TH Köln</a></li>
|
||
<li><a href="#c.-aufsichtsbehörde-in-datenschutzangelegenheiten">C. Aufsichtsbehörde in Datenschutzangelegenheiten</a></li>
|
||
<li><a href="#d.-allgemeines-zur-datenverarbeitung">D. Allgemeines zur Datenverarbeitung</a></li>
|
||
<li><a href="#e.-bereitstellung-der-webseite-und-erstellung-von-logfiles">E. Bereitstellung der Webseite und Erstellung von Logfiles</a></li>
|
||
<li><a href="#f.-rechte-betroffener-personen">F. Rechte betroffener Personen</a></li>
|
||
</ul>
|
||
<h2 id="a.-name-und-anschrift-des-verantwortlichen">A. Name und Anschrift des Verantwortlichen</h2>
|
||
<p>Verantwortlicher im Sinne der EU-Datenschutzgrundverordnung (DS-GVO) und anderer nationaler Datenschutzgesetze sowie sonstiger datenschutzrechtlicher Bestimmungen ist:<br />
|
||
<br />
|
||
TH Köln<br />
|
||
Gruppe für Daten- und Anwendungssicherheit<br />
|
||
Prof. Dr. Luigi Lo Iacono<br />
|
||
Betzdorfer Str. 2<br />
|
||
50679 Köln<br />
|
||
T: +49 221-8275-2527<br />
|
||
E-Mail: luigi.lo_iacono@th-koeln.de<br />
|
||
Webseite: cpdos.org</p>
|
||
<h2 id="b.-name-und-anschrift-der-datenschutzbeauftragten-der-th-köln">B. Name und Anschrift der Datenschutzbeauftragten der TH Köln</h2>
|
||
<p>Walter Keens<br />
|
||
Claudiusstraße 1<br />
|
||
50678 Köln<br />
|
||
T: +49 221 8275 3108<br />
|
||
E: datenschutzbeauftragter@th-koeln.de</p>
|
||
<p>Bernadette Schmitz<br />
|
||
Claudiusstraße 1<br />
|
||
50678 Köln<br />
|
||
T: +49 221 8275 3994<br />
|
||
E: datenschutzbeauftragter@th-koeln.de</p>
|
||
<h2 id="c.-aufsichtsbehörde-in-datenschutzangelegenheiten">C. Aufsichtsbehörde in Datenschutzangelegenheiten</h2>
|
||
<p>Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)<br />
|
||
Kavalleriestr. 2-4<br />
|
||
40213 Düsseldorf<br />
|
||
Telefon: 0211/38424-0<br />
|
||
Fax: 0211/38424-10<br />
|
||
E-Mail: poststelle@ldi.nrw.de</p>
|
||
<h2 id="d.-allgemeines-zur-datenverarbeitung">D. Allgemeines zur Datenverarbeitung</h2>
|
||
<p>1. Umfang der Verarbeitung personenbezogener Daten</p>
|
||
<p>Die TH Köln verarbeitet personenbezogene Daten von Webseiten-Nutzenden grundsätzlich nur, soweit dies zur Bereitstellung einer funktionsfähigen Webseite sowie der Inhalte und Angebote erforderlich ist. Die Verarbeitung personenbezogener Daten von Webseiten-Nutzenden erfolgt regelmäßig nur gemäß erteilter Einwilligung. Eine Ausnahme gilt in solchen Fällen, in denen eine vorherige Einholung einer Einwilligung aus tatsächlichen Gründen nicht möglich ist und die Verarbeitung der Daten durch gesetzliche Vorschriften erlaubt ist.</p>
|
||
<p>2. Rechtsgrundlage für die Verarbeitung personenbezogener Daten</p>
|
||
<p>Soweit die TH Köln personenbezogene Daten gemäß erteilter Einwilligung verarbeitet, stellt Art. 6 Abs. 1 lit. a DS-GVO die Rechtsgrundlage dar.</p>
|
||
<p>Bei der Verarbeitung von personenbezogenen Daten, die zur Erfüllung eines Vertrages, dessen Vertragspartei die betroffene Person ist, erforderlich ist, ergibt sich die Rechtsgrundlage aus Art. 6 Abs. 1 lit. b DS-GVO. Dies gilt auch für Verarbeitungstätigkeiten, die zur Durchführung vorvertraglicher Maßnahmen erforderlich sind.</p>
|
||
<p>Soweit eine Verarbeitung personenbezogener Daten zur Erfüllung einer rechtlichen Verpflichtung erforderlich ist, der die TH Köln als Körperschaft des öffentlichen Rechts unterliegt, dient Art. 6 Abs. 1 lit. c DS-GVO als Rechtsgrundlage.</p>
|
||
<p>Für den Fall, dass lebenswichtige Interessen der betroffenen Person oder einer anderen natürlichen Person eine Verarbeitung personenbezogener Daten erforderlich machen, stellt Art. 6 Abs. 1 lit. d DS-GVO die Rechtsgrundlage dar.</p>
|
||
<p>Ist die Verarbeitung zur Wahrung eines berechtigten Interesses der TH Köln oder eines Dritten erforderlich und überwiegen die Interessen, Grundrechte und Grundfreiheiten des Betroffenen das erstgenannte Interesse nicht, so ergibt sich die Rechtsgrundlage aus Art. 6 Abs. 1 lit. f DS-GVO.</p>
|
||
<p>3. Datenlöschung und Speicherdauer</p>
|
||
<p>Die personenbezogenen Daten der betroffenen Person werden gelöscht oder gesperrt, sobald der Zweck der Speicherung entfällt. Eine Speicherung kann darüber hinaus erfolgen, wenn dies durch den europäischen oder nationalen Gesetzgeber in unionsrechtlichen Verordnungen, Gesetzen oder sonstigen Vorschriften, denen die TH Köln unterliegt, vorgesehen wurde. Eine Sperrung oder Löschung der Daten erfolgt auch dann, wenn eine durch die genannten Normen vorgeschriebene Speicherfrist abläuft, es sei denn, dass eine Erforderlichkeit zur weiteren Speicherung der Daten für einen Vertragsabschluss, eine Vertragserfüllung oder zur Erfüllung einer Aufbewahrungspflicht besteht.</p>
|
||
<h2 id="e.-bereitstellung-der-webseite-und-erstellung-von-logfiles">E. Bereitstellung der Webseite und Erstellung von Logfiles</h2>
|
||
<p>1. Beschreibung und Umfang der Datenverarbeitung</p>
|
||
<p>Bei jedem Aufruf unserer Internetseite erfasst die TH Köln automatisiert Daten und Informationen vom Computersystem des aufrufenden Rechners.</p>
|
||
<p>Folgende Daten werden hierbei erhoben:</p>
|
||
<ol type="a">
|
||
<li>Die IP-Adresse der Nutzenden</li>
|
||
<li>Datum und Uhrzeit des Zugriffs</li>
|
||
<li>Webseiten, die vom System der Nutzenden über unsere Webseite aufgerufen werden</li>
|
||
<li>Das Betriebssystem der Nutzenden</li>
|
||
<li>Informationen über den Browsertyp und die verwendete Version</li>
|
||
<li>Webseiten, von denen das System der Nutzenden auf unsere Internetseite gelangt</li>
|
||
<li>Den Internet-Service-Provider der Nutzenden</li>
|
||
</ol>
|
||
<p>Die Daten werden ebenfalls in den Logfiles von Systemen der TH Köln gespeichert. Eine Speicherung dieser Daten zusammen mit anderen personenbezogenen Daten der Nutzenden findet nicht statt. </p>
|
||
<p>2. Rechtsgrundlage für die Datenverarbeitung</p>
|
||
<p>Rechtsgrundlage für die Speicherung der Daten ist Art. 6 Abs. 1 lit. a DS-GVO.</p>
|
||
<p>3. Zweck der Datenverarbeitung</p>
|
||
<p>Die vorübergehende Speicherung der IP-Adresse durch das System ist notwendig, um eine Auslieferung der Webseite an den Rechner der Nutzenden zu ermöglichen. Hierfür muss die IP-Adresse der Nutzenden für die Dauer der Sitzung gespeichert bleiben.</p>
|
||
<p>Die Speicherung in Logfiles erfolgt, um die Funktionsfähigkeit der Webseite sicherzustellen. Zudem dienen die Daten zur Optimierung der Webseite und zur Sicherstellung der Sicherheit der informationstechnischen Systeme der TH Köln. Eine Auswertung der Daten zu Marketingzwecken findet in diesem Zusammenhang nicht statt.</p>
|
||
<p>Das berechtigte Interesse der TH Köln an der Datenverarbeitung nach Art. 6 Abs. 1 lit. f DS-GVO stützt sich auf diese Zwecke.</p>
|
||
<p>4. Dauer der Speicherung</p>
|
||
<p>Die Daten werden gelöscht, sobald sie für die Erreichung des Zwecks ihrer Erhebung nicht mehr erforderlich sind. Im Falle der Erfassung der Daten zur Bereitstellung der Webseite ist dies der Fall, wenn die jeweilige Sitzung beendet ist.</p>
|
||
<p>Im Falle der Speicherung der Daten in Logfiles ist dies nach spätestens sieben Tagen der Fall. In diesem Fall werden die IP-Adressen der Nutzer gelöscht oder verfremdet, sodass eine Zuordnung des aufrufenden Clients nicht mehr möglich ist.</p>
|
||
<p>5. Widerspruchs- und Beseitigungsmöglichkeit</p>
|
||
<p>Die Erfassung der Daten zur Bereitstellung der Webseite und die Speicherung der Daten in Logfiles ist für den Betrieb der Internetseite zwingend erforderlich. Es besteht folglich seitens der Nutzenden keine Widerspruchsmöglichkeit. </p>
|
||
<h2 id="f.-rechte-betroffener-personen">F. Rechte betroffener Personen</h2>
|
||
<p>Werden personenbezogene Daten von Ihnen verarbeitet, gehören Sie zu den Betroffenen i.S.d. DS-GVO und es stehen Ihnen folgende Rechte gegenüber der TH Köln zu:</p>
|
||
<p>1. Auskunftsrecht</p>
|
||
<p>Sie können von der TH Köln eine Bestätigung darüber verlangen, ob personenbezogene Daten, die Sie betreffen, von uns verarbeitet werden. Liegt eine solche Verarbeitung vor, können Sie von der TH Köln über folgende Informationen Auskunft verlangen:</p>
|
||
<ol type="a">
|
||
<li><p>die Zwecke, zu denen die personenbezogenen Daten verarbeitet werden;</p></li>
|
||
<li><p>die Kategorien von personenbezogenen Daten, welche verarbeitet werden;</p></li>
|
||
<li><p>die Empfänger bzw. die Kategorien von Empfängern, gegenüber denen die Sie betreffenden personenbezogenen Daten offengelegt wurden oder noch offengelegt werden;</p></li>
|
||
<li><p>die geplante Dauer der Speicherung der Sie betreffenden personenbezogenen Daten oder, falls konkrete Angaben hierzu nicht möglich sind, Kriterien für die Festlegung der Speicherdauer;</p></li>
|
||
<li><p>das Bestehen eines Rechts auf Berichtigung oder Löschung der Sie betreffenden personenbezogenen Daten, eines Rechts auf Einschränkung der Verarbeitung durch die TH Köln oder eines Widerspruchsrechts gegen diese Verarbeitung;</p></li>
|
||
<li><p>das Bestehen eines Beschwerderechts bei einer Aufsichtsbehörde;</p></li>
|
||
<li><p>alle verfügbaren Informationen über die Herkunft der Daten, wenn die personenbezogenen Daten nicht bei der betroffenen Person erhoben werden;</p></li>
|
||
<li><p>das Bestehen einer automatisierten Entscheidungsfindung einschließlich Profiling gemäß Art. 22 Abs. 1 und 4 DS-GVO und – zumindest in diesen Fällen – aussagekräftige Informationen über die involvierte Logik sowie die Tragweite und die angestrebten Auswirkungen einer derartigen Verarbeitung für die betroffene Person.</p></li>
|
||
</ol>
|
||
<p>Ihnen steht das Recht zu, Auskunft darüber zu verlangen, ob die Sie betreffenden personenbezogenen Daten in ein Drittland oder an eine internationale Organisation übermittelt werden. In diesem Zusammenhang können Sie verlangen, über die geeigneten Garantien gem. Art. 46 DS-GVO im Zusammenhang mit der Übermittlung unterrichtet zu werden.</p>
|
||
<p>Dieses Auskunftsrecht kann insoweit beschränkt werden, als es voraussichtlich die Verwirklichung der Forschungs- oder Statistikzwecke unmöglich macht oder ernsthaft beeinträchtigt und die Beschränkung für die Erfüllung der Forschungs- oder Statistikzwecke notwendig ist.</p>
|
||
<p>2. Recht auf Berichtigung</p>
|
||
<p>Sie haben ein Recht auf Berichtigung und/oder Vervollständigung gegenüber der TH Köln, sofern die verarbeiteten personenbezogenen Daten, die Sie betreffen, unrichtig oder unvollständig sind. Die TH Köln hat die Berichtigung unverzüglich vorzunehmen.<br />
|
||
Ihr Recht auf Berichtigung kann insoweit beschränkt werden, als es voraussichtlich die Verwirklichung der Forschungs- oder Statistikzwecke unmöglich macht oder ernsthaft beeinträchtigt und die Beschränkung für die Erfüllung der Forschungs- oder Statistikzwecke notwendig ist.</p>
|
||
<p>3. Recht auf Einschränkung der Verarbeitung</p>
|
||
<p>Unter den folgenden Voraussetzungen können Sie die Einschränkung der Verarbeitung der Sie betreffenden personenbezogenen Daten verlangen:</p>
|
||
<ol type="a">
|
||
<li><p>wenn Sie die Richtigkeit der Sie betreffenden personenbezogenen Daten für eine Dauer bestreiten, die es der TH Köln ermöglicht, die Richtigkeit der personenbezogenen Daten zu überprüfen;</p></li>
|
||
<li><p>die Verarbeitung unrechtmäßig ist und Sie die Löschung der personenbezogenen Daten ablehnen und stattdessen die Einschränkung der Nutzung der personenbezogenen Daten verlangen;</p></li>
|
||
<li><p>die TH Köln die personenbezogenen Daten für die Zwecke der Verarbeitung nicht länger benötigt, Sie diese jedoch zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen benötigen, oder</p></li>
|
||
<li><p>wenn Sie Widerspruch gegen die Verarbeitung gemäß Art. 21 Abs. 1 DS-GVO eingelegt haben und noch nicht feststeht, ob die berechtigten Gründe der TH Köln gegenüber Ihren Gründen überwiegen.</p></li>
|
||
</ol>
|
||
<p>Wurde die Verarbeitung der Sie betreffenden personenbezogenen Daten eingeschränkt, dürfen diese Daten – von ihrer Speicherung abgesehen – nur mit Ihrer Einwilligung oder zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen oder zum Schutz der Rechte einer anderen natürlichen oder juristischen Person oder aus Gründen eines wichtigen öffentlichen Interesses der Union oder eines Mitgliedstaats verarbeitet werden.<br />
|
||
Wurde die Einschränkung der Verarbeitung nach den o.g. Voraussetzungen eingeschränkt, werden Sie von der TH Köln unterrichtet bevor die Einschränkung aufgehoben wird.</p>
|
||
<p>Ihr Recht auf Einschränkung der Verarbeitung kann insoweit beschränkt werden, als es voraussichtlich die Verwirklichung der Forschungs- oder Statistikzwecke unmöglich macht oder ernsthaft beeinträchtigt und die Beschränkung für die Erfüllung der Forschungs- oder Statistikzwecke notwendig ist.</p>
|
||
<p>4. Recht auf Löschung</p>
|
||
<ol type="a">
|
||
<li>Löschungspflicht<br />
|
||
Sie können von der TH Köln verlangen, dass die Sie betreffenden personenbezogenen Daten unverzüglich gelöscht werden, und die TH Köln ist verpflichtet, diese Daten unverzüglich zu löschen, sofern einer der folgenden Gründe zutrifft:</li>
|
||
</ol>
|
||
<ul>
|
||
<li>Die Sie betreffenden personenbezogenen Daten sind für die Zwecke, für die sie erhoben oder auf sonstige Weise verarbeitet wurden, nicht mehr notwendig.</li>
|
||
<li>Sie widerrufen Ihre Einwilligung, auf die sich die Verarbeitung gem. Art. 6 Abs. 1 lit. a oder Art. 9 Abs. 2 lit. a DS-GVO stützte, und es fehlt an einer anderweitigen Rechtsgrundlage für die Verarbeitung.</li>
|
||
<li>Sie legen gem. Art. 21 Abs. 1 DS-GVO Widerspruch gegen die Verarbeitung ein und es liegen keine vorrangigen berechtigten Gründe für die Verarbeitung vor, oder Sie legen gem. Art. 21 Abs. 2 DS-GVO Widerspruch gegen die Verarbeitung ein.</li>
|
||
<li>Die Sie betreffenden personenbezogenen Daten wurden unrechtmäßig verarbeitet.</li>
|
||
<li>Die Löschung der Sie betreffenden personenbezogenen Daten ist zur Erfüllung einer rechtlichen Verpflichtung nach dem Unionsrecht oder dem Recht der Mitgliedstaaten erforderlich, dem die TH Köln unterliegt.</li>
|
||
<li>Die Sie betreffenden personenbezogenen Daten wurden in Bezug auf angebotene Dienste der Informationsgesellschaft gemäß Art. 8 Abs. 1 DS-GVO erhoben.</li>
|
||
</ul>
|
||
<ol start="2" type="a">
|
||
<li><p>Information an Dritte<br />
|
||
Hat die TH Köln die Sie betreffenden personenbezogenen Daten öffentlich gemacht und ist sie gem. Art. 17 Abs. 1 DS-GVO zu deren Löschung verpflichtet, so trifft sie unter Berücksichtigung der verfügbaren Technologie und der Implementierungskosten angemessene Maßnahmen, auch technischer Art, um für die Datenverarbeitung TH Köln, die die personenbezogenen Daten verarbeiten, darüber zu informieren, dass Sie als betroffene Person von Ihnen die Löschung aller Links zu diesen personenbezogenen Daten oder von Kopien oder Replikationen dieser personenbezogenen Daten verlangt haben.</p></li>
|
||
<li><p>Ausnahmen<br />
|
||
Das Recht auf Löschung besteht nicht, soweit die Verarbeitung erforderlich ist</p></li>
|
||
</ol>
|
||
<ul>
|
||
<li>zur Ausübung des Rechts auf freie Meinungsäußerung und Information;</li>
|
||
<li>zur Erfüllung einer rechtlichen Verpflichtung, die die Verarbeitung nach dem Recht der Union oder der Mitgliedstaaten, dem die TH Köln unterliegt, erfordert, oder zur Wahrnehmung einer Aufgabe, die im öffentlichen Interesse liegt oder in Ausübung öffentlicher Gewalt erfolgt, die der TH Köln übertragen wurde;</li>
|
||
<li>aus Gründen des öffentlichen Interesses im Bereich der öffentlichen Gesundheit gemäß Art. 9 Abs. 2 lit. h und i sowie Art. 9 Abs. 3 DS-GVO;</li>
|
||
<li>für im öffentlichen Interesse liegende Archivzwecke, wissenschaftliche oder historische Forschungszwecke oder für statistische Zwecke gem. Art. 89 Abs. 1 DS-GVO, soweit das unter Abschnitt a) genannte Recht voraussichtlich die Verwirklichung der Ziele dieser Verarbeitung unmöglich macht oder ernsthaft beeinträchtigt, oder</li>
|
||
<li>zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen.</li>
|
||
</ul>
|
||
<p>5. Recht auf Unterrichtung<br />
|
||
Haben Sie das Recht auf Berichtigung, Löschung oder Einschränkung der Verarbeitung gegenüber der TH Köln geltend gemacht, ist dieser verpflichtet, allen Empfängern, denen die Sie betreffenden personenbezogenen Daten offengelegt wurden, diese Berichtigung oder Löschung der Daten oder Einschränkung der Verarbeitung mitzuteilen, es sei denn, dies erweist sich als unmöglich oder ist mit einem unverhältnismäßigen Aufwand verbunden.<br />
|
||
Ihnen steht gegenüber der TH Köln das Recht zu, über diese Empfänger unterrichtet zu werden.</p>
|
||
<p>6. Recht auf Datenübertragbarkeit</p>
|
||
<p>Sie haben das Recht, die Sie betreffenden personenbezogenen Daten, die Sie der TH Köln bereitgestellt haben, in einem strukturierten, gängigen und maschinenlesbaren Format zu erhalten. Außerdem haben Sie das Recht diese Daten einem anderen TH Köln ohne Behinderung durch den TH Köln, dem die personenbezogenen Daten bereitgestellt wurden, zu übermitteln, sofern</p>
|
||
<ol type="a">
|
||
<li><p>die Verarbeitung auf einer Einwilligung gem. Art. 6 Abs. 1 lit. a DS-GVO oder Art. 9 Abs. 2 lit. a DS-GVO oder auf einem Vertrag gem. Art. 6 Abs. 1 lit. b DS-GVO beruht und</p></li>
|
||
<li><p>die Verarbeitung mithilfe automatisierter Verfahren erfolgt.</p></li>
|
||
</ol>
|
||
<p>In Ausübung dieses Rechts haben Sie ferner das Recht, zu erwirken, dass die Sie betreffenden personenbezogenen Daten direkt von der TH Köln einem anderen Verantwortlichen übermittelt werden, soweit dies technisch machbar ist. Freiheiten und Rechte anderer Personen dürfen hierdurch nicht beeinträchtigt werden.<br />
|
||
Das Recht auf Datenübertragbarkeit gilt nicht für eine Verarbeitung personenbezogener Daten, die für die Wahrnehmung einer Aufgabe erforderlich ist, die im öffentlichen Interesse liegt oder in Ausübung öffentlicher Gewalt erfolgt, die der TH Köln übertragen wurde.</p>
|
||
<p>7. Widerspruchsrecht</p>
|
||
<p>Sie haben das Recht, aus Gründen, die sich aus ihrer besonderen Situation ergeben, jederzeit gegen die Verarbeitung der Sie betreffenden personenbezogenen Daten, die aufgrund von Art. 6 Abs. 1 lit. e oder f DS-GVO erfolgt, Widerspruch einzulegen; dies gilt auch für ein auf diese Bestimmungen gestütztes Profiling.</p>
|
||
<p>Die TH Köln verarbeitet die Sie betreffenden personenbezogenen Daten nicht mehr, es sei denn, sie kann zwingende schutzwürdige Gründe für die Verarbeitung nachweisen, die Ihre Interessen, Rechte und Freiheiten überwiegen, oder die Verarbeitung dient der Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen.</p>
|
||
<p>Sie haben auch das Recht, aus Gründen, die sich aus Ihrer besonderen Situation ergeben, bei der Verarbeitung Sie betreffender personenbezogener Daten, die zu wissenschaftlichen oder historischen Forschungszwecken oder zu statistischen Zwecken gem. Art. 89 Abs. 1 DS-GVO erfolgt, dieser zu widersprechen.</p>
|
||
<p>Ihr Widerspruchsrecht kann insoweit beschränkt werden, als es voraussichtlich die Verwirklichung der Forschungs- oder Statistikzwecke unmöglich macht oder ernsthaft beeinträchtigt und die Beschränkung für die Erfüllung der Forschungs- oder Statistikzwecke notwendig ist.</p>
|
||
<p>8. Recht auf Widerruf der datenschutzrechtlichen Einwilligungserklärung</p>
|
||
<p>Sie haben das Recht, Ihre datenschutzrechtliche Einwilligungserklärung jederzeit zu widerrufen. Durch den Widerruf der Einwilligung wird die Rechtmäßigkeit der aufgrund der Einwilligung bis zum Widerruf erfolgten Verarbeitung nicht berührt.</p>
|
||
<p>9. Automatisierte Entscheidung im Einzelfall einschließlich Profiling</p>
|
||
<p>Sie haben das Recht, nicht einer ausschließlich auf einer automatisierten Verarbeitung – einschließlich Profiling – beruhenden Entscheidung unterworfen zu werden, die Ihnen gegenüber rechtliche Wirkung entfaltet oder Sie in ähnlicher Weise erheblich beeinträchtigt. Dies gilt nicht, wenn die Entscheidung</p>
|
||
<ol type="a">
|
||
<li><p>für den Abschluss oder die Erfüllung eines Vertrags zwischen Ihnen und der TH Köln erforderlich ist,</p></li>
|
||
<li><p>aufgrund von Rechtsvorschriften der Union oder der Mitgliedstaaten, denen die TH Köln unterliegt, zulässig ist und diese Rechtsvorschriften angemessene Maßnahmen zur Wahrung Ihrer Rechte und Freiheiten sowie Ihrer berechtigten Interessen enthalten oder</p></li>
|
||
<li><p>mit Ihrer ausdrücklichen Einwilligung erfolgt.</p></li>
|
||
</ol>
|
||
<p>Allerdings dürfen diese Entscheidungen nicht auf besonderen Kategorien personenbezogener Daten nach Art. 9 Abs. 1 DS-GVO beruhen, sofern nicht Art. 9 Abs. 2 lit. a oder g DS-GVO gilt und angemessene Maßnahmen zum Schutz der Rechte und Freiheiten sowie Ihrer berechtigten Interessen getroffen wurden. Hinsichtlich der in (a) und (c) genannten Fälle trifft die TH Köln angemessene Maßnahmen, um die Rechte und Freiheiten sowie Ihre berechtigten Interessen zu wahren, wozu mindestens das Recht auf Erwirkung des Eingreifens einer Person seitens der TH Köln, auf Darlegung des eigenen Standpunkts und auf Anfechtung der Entscheidung gehört.</p>
|
||
<p>10. Recht auf Beschwerde bei einer Aufsichtsbehörde</p>
|
||
<p>Unbeschadet eines anderweitigen verwaltungsrechtlichen oder gerichtlichen Rechtsbehelfs steht Ihnen das Recht auf Beschwerde bei einer Aufsichtsbehörde, insbesondere in dem Mitgliedstaat Ihres Aufenthaltsorts, Ihres Arbeitsplatzes oder des Orts des mutmaßlichen Verstoßes, zu, wenn Sie der Ansicht sind, dass die Verarbeitung der Sie betreffenden personenbezogenen Daten gegen die DS-GVO verstößt.</p>
|
||
<p>Die Aufsichtsbehörde, bei der die Beschwerde eingereicht wurde, unterrichtet den Beschwerdeführer über den Stand und die Ergebnisse der Beschwerde einschließlich der Möglichkeit eines gerichtlichen Rechtsbehelfs nach Art. 78 DS-GVO.</p>
|
||
|
||
</div>
|
||
<div class="modal-footer">
|
||
<button type="button" class="btn btn-default" data-dismiss="modal">Close</button>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
<script type="text/javascript" src="/js/jquery.min.js"></script>
|
||
|
||
<script type="text/javascript" src="/js/bootstrap.min.js"></script>
|
||
|
||
<script type="text/javascript">
|
||
|
||
$('ul.nav li.dropdown').hover(function() {
|
||
$(this).find('.dropdown-menu').stop(true, true).delay(100).fadeIn(300);
|
||
}, function() {
|
||
$(this).find('.dropdown-menu').stop(true, true).delay(100).fadeOut(300);
|
||
});
|
||
|
||
$("[data-toggle=popover]").each(function(i, obj) {
|
||
|
||
$(this).popover({
|
||
html: true,
|
||
content: function() {
|
||
var id = $(this).attr('id')
|
||
return $('#popover-content-' + id).html();
|
||
}
|
||
});
|
||
|
||
});
|
||
|
||
var offset = 55;
|
||
|
||
var offsetHeight = 50;
|
||
$('body').scrollspy({ target: '#navbar' , offset: offset })
|
||
$('.navbar li a').click(function(event) {
|
||
event.preventDefault();
|
||
//console.log($($(this).attr('href'))[0] + "helello");
|
||
$($(this).attr('href'))[0].scrollIntoView();
|
||
scrollBy(0, -offsetHeight);
|
||
});
|
||
|
||
$('[data-toggle="popover"]').popover()
|
||
$('[data-toggle="popover"]').on('click',function(e){
|
||
e.preventDefault();
|
||
}).popover();
|
||
</script>
|
||
|
||
|
||
<footer class="footer">
|
||
<div class="container">
|
||
<div class="row">
|
||
<div class="col-md-6 col-xs-6"><p class="text-muted small visible-lg visible-md">Copyright © Data & Application Security Group, TH Köln - University of Applied Sciences <br> Last updated March 30, 2020</p>
|
||
<p class="text-muted small visible-xs visible-sm">Copyright © DAS Group <br> Last updated 30.03.2020</p>
|
||
</div>
|
||
<div class="col-md-6 col-xs-6">
|
||
<p class="text-muted text-right small">
|
||
<a data-toggle="modal" href="#" data-target="#imprintModal" style="display:block">Imprint</a>
|
||
</p></div>
|
||
</div>
|
||
|
||
</div>
|
||
</footer>
|
||
</body>
|
||
<script type="text/javascript" src="/js/prism.js"></script>
|
||
|
||
</html> |