How Third-Party Code Enables Web Attacks

248 views
•
February 28, 2020
by
RSAC Cybersecurity
YouTube video player
How Third-Party Code Enables Web Attacks

TL;DR

Third-party code can expose website visitors and organizations to data theft, tracking, malware, fraud, and targeted manipulation, even when the website’s own code is secure. Organizations must understand which external companies execute code on their digital properties and hold those suppliers accountable, because a compromised partner can redirect users, steal payment details, drop payloads, or collect sensitive behavioral information.

Transcript

Good afternoon, everybody. Welcome to the two fifty session, Third-Party Code, where data breaches, election meddling, and ad fraud converge. Our two speakers today are Mark Grantz. Mark is from the US Secret Service Technical Security Division, and we have Chris Olson, founder and CEO of Media Trust. I ask if you could please, uh, silence your cel... Read More

Key Insights

  • Third-party code is any source code that was not written by the owned and operated groups within the company whose website a visitor opens. It can include advertising, analytics, externally produced content, redirects, and code supplied through third, fourth, fifth, or later parties.
  • A website can create security exposure without suffering a direct breach. Ticketmaster’s own systems were not identified as the breached component in the example presented, because attackers compromised a third-party web analytics provider connected to its website.
  • Magecart attacks work by compromising website JavaScript and using it to skim credit card numbers while customers complete purchases. British Airways, Newegg, and Ticketmaster were cited as prominent organizations associated with such incidents.
  • Advertising infrastructure is designed to collect information about people’s preferences and place messages before selected audiences. Ad networks and ad exchanges developed because advertisers wanted their promotions shown to the people considered most relevant to what they were selling.
  • Third-party code can constitute most of the code executing on a website. The presentation reports third-party proportions of eighty-four percent for hotel and gaming websites and eighty-two percent for banking websites, despite the sensitive relationships these businesses maintain with customers.
  • Presidential candidate websites can involve fifty, eighty, one hundred, or two hundred companies executing code before a visitor registers. The code is described as supporting recognition, tracking, marketing, and the sale of visitor information throughout the digital ecosystem.
  • Political websites examined in the cited study had five hundred and nine companies rendering source code across the candidates’ digital assets as of the middle of November. Nine of those companies were from China, and all nine dropped cookies used to recognize consumers.
  • Organizational accountability extends beyond code controlled by internal web developers. Companies need to understand which external suppliers render code for visitors because compromised partners can enable phishing redirects, payload drops, crypto-mining, keylogging, bloatware, malvertising, and sensitive behavioral tracking.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is third-party code on a website?

Third-party code is source code executing on a website that was not written by the owned and operated groups within the company a visitor intended to reach. It can originate from advertisers, analytics providers, content suppliers, ad networks, exchanges, and additional parties reached through redirects or calls. The presentation describes these dependencies as third-to-nth-party code because several layers of companies can participate.

Q: How can third-party code cause a data breach?

Third-party code can create a path into a website experience when an external supplier is compromised. Attackers may alter JavaScript, redirect visitors, deliver malicious payloads, or capture information entered during a transaction. The organization’s internally managed code may remain secure, but customers can still be exposed because code from the compromised partner executes in their browsers while they use the organization’s website.

Q: How does Magecart steal credit card information?

Magecart attackers compromise JavaScript connected to a website and use that code to skim credit card numbers while customers move through a purchase page. The presentation cites British Airways, Newegg, and Ticketmaster as prominent cases. Its main lesson is that the affected customer experience may depend on external code, so the publicly associated company is not necessarily the organization directly breached.

Q: Was Ticketmaster directly breached in the Magecart case?

Ticketmaster was not described as the directly breached organization in the case discussed. A third-party company providing web analytics to Ticketmaster was compromised. Nevertheless, Ticketmaster’s name appeared in the headlines because customers encountered the risk through its website. The example shows why organizations remain exposed to reputational and customer harm when an outside supplier fails to maintain a secure environment.

Q: Why do websites use advertising networks and analytics?

Websites use advertising networks and analytics to understand people’s likes and dislikes, place advertisements before relevant audiences, and support online buying and selling. The presentation says advertising helps finance communication, education, and entertainment on the internet. Analytics makes that advertising more efficient, but the resulting ecosystem also introduces many external companies and code relationships that website owners may not fully control.

Q: How much website code can come from third parties?

The presentation reports that third-party code represents eighty-four percent on hotel and gaming websites and eighty-two percent on banking websites. It also explains that media sites can contain substantial externally supplied advertising and content. These figures support the presenters’ warning that the majority of code executing during a visit may sit outside the direct ownership and operational control of the company serving the website.

Q: How does third-party code affect political websites?

Political websites are designed to recognize visitors and market to them, according to the presentation. Before a visitor registers, fifty, eighty, one hundred, or two hundred companies may render code on a candidate’s site. A cited study found five hundred and nine companies across the candidates’ digital assets, including nine companies from China that dropped cookies used to recognize consumers and their visits.

Q: How should organizations manage third-party code risk?

Organizations should identify which companies render source code on their websites and treat those suppliers as part of their security responsibility. Protecting owned code through application security and development security practices does not address every external dependency. Accountability must extend to providers that deliver advertising, analytics, redirects, and other executable content because their compromise can expose visitors to theft, tracking, malware delivery, fraud, or manipulation.

Summary & Key Takeaways

  • Websites often combine their own source code with extensive third-party code for advertising, analytics, content delivery, and user tracking. The presenters argue that security teams may protect the code under their direct control while lacking a complete inventory of the external companies whose code ultimately executes in each visitor’s browser.

  • The Magecart investigation illustrates the consequences of this dependency. Attackers can compromise JavaScript associated with a website and skim credit card details during purchases. In the Ticketmaster case discussed, a third-party web analytics provider was breached rather than Ticketmaster itself, yet Ticketmaster’s recognizable name became associated with the incident in public headlines.

  • The advertising ecosystem connects websites through ad networks, exchanges, redirects, analytics, and multiple layers of outside suppliers. According to the presentation, third-party code accounts for eighty-four percent on hotel and gaming sites and eighty-two percent on banking sites, creating a shared environment where tracking, malvertising, disinformation, election meddling, and other attacks can converge.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚