Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

June 19, 2009 12:00 AM

Opera-Unite lets standard users share content on the Internet from behind your corporate firewall.

Windows IT Pro
InstantDoc ID #102334
Rating: (2)

Version 10 of Opera’s web browser, which is currently in alpha, includes a feature called Opera-Unite. Opera-Unite is a web server included with the Opera web browser. This sounds like it is going to be a security nightmare.

From the Opera Unite Website (unite.opera.com):

Opera Unite Allows You to Easily Share Your Data … you can even run chat rooms and host entire web sites.

Opera Unite works behind firewalls and network address translation devices through the Opera Unite Proxy. (http://dev.opera.com/articles/view/opera-unite-developer-primer/)

Which means that even if you’ve got a firewall in place, unless you specifically tailor your policies, users on your internal network that have the Opera browser installed can run web servers off their desktop PCs that are available through Opera Unite to hosts on the Internet.

What is even more scary is that once a user with admin privileges has installed Opera 10 on a Windows 7 computer and configured a firewall rule to allow Opera.exe, a user with standard privileges can set up their own website that is available to the Internet. They don’t need to elevate privileges, they just need to be able to run Opera.

When running Opera 10 with Opera Unite (which can be enabled by a standard user), a standard user can make directories publically available to the Internet even if they are behind NAT and an external firewall. I tested this by installing Opera 10 and enabling on a VM that was running behind my NAT firewall. Before Opera-Unite would function, it did require a firewall rule be added for Opera.exe, though it wasn’t clear that this would enable web server functionality. I then ran Opera as a standard user and was able to activate Opera Unite and configure a public web server, able to share any directory with the Internet that I had access to.

At a minimum before this goes gold, Opera should ensure that you cannot turn on Opera Unite without elevating privileges.

Related Content:

ARTICLE TOOLS

Comments
  • Ed
    3 years ago
    Jun 23, 2009

    First you got Chrome allowing non-administrative users to install and installing not in c:\\program files but in their own profile [this info as of the last time I looked at Chrome] and now this? Network admins will be busy!

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.