Attacks/Breaches
6/28/2007
07:35 AM
50%
50%

Not One Size Fits All

One man's firewall is another man's kludge

3:35 PM -- Sometimes, what's good for one application just isn't good for another.

I've been in the game for a long time and get to see a lot of interesting tactics to prevent exploitation. Recently, I've been involved in auditing a software application, and one of the interesting aspects is how security theory varies from one technology to another.

With Websites, for instance, one of the reasons firewalls have proven to be fairly overkill is because often attackers are coming from addresses where many other people are also originating from (through network address translation). So you can't simply block by an IP address -- yet you feel you must block by them because you are getting attacked by an IP address.

Now look at software. If software running on your desktop detects that someone is attempting to do something malicious, it may be OK to block the request completely -- unlike with a firewall. Who cares if it breaks for a single instance of a single Web page? It's far better than having your local machine compromised. Rather than attempting to handle an error, let your application fail in a safe way. When the system starts acting responsibly again, your application can start running again in a sane way.

While the network can cause major outages if it fails, the worst that a local process can do is cause you to reboot. Setting up a denial-of-service situation on the desktop affects one user temporarily, whereas on the network, tens of thousands of users, as in the case of AOL's proxies.

One is acceptable; the other can be a significant detriment to your business. Different security people work on different systems and with different paradigms, so remember that one security professional's advice on blocking exploits does not fit all circumstances, especially if they aren't working in the same industry you are.

— RSnake is a red-blooded lumberjack whose rants can also be found at Ha.ckers and F*the.net. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9605
Published: 2015-09-04
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character in the login and password parameters to webup...

CVE-2015-2990
Published: 2015-09-04
Directory traversal vulnerability in NEOJAPAN desknet NEO 2.0R1.0 through 2.5R1.4 allows remote authenticated users to read arbitrary files via a crafted parameter.

CVE-2015-2991
Published: 2015-09-04
Buffer overflow in NScripter before 3.00 allows remote attackers to execute arbitrary code via crafted save data.

CVE-2015-5612
Published: 2015-09-04
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image.

CVE-2015-5688
Published: 2015-09-04
Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.