Re: [fw-wiz] Application-level Attacks

From: Frank Knobbe (frank_at_knobbe.us)
Date: 01/28/05

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Multiple firewalls from different manufactureres"
    To: Devdas Bhagat <devdas@dvb.homelinux.org>
    Date: Fri, 28 Jan 2005 14:49:26 -0600
    
    
    

    On Sat, 2005-01-29 at 01:10 +0530, Devdas Bhagat wrote:
    > The exposure of applications has increased, but ye olde Sendmail bug
    > and the BIND exploit du jour and the Internet Explorer sieve are still
    > application layer bugs.

    I think we first have to define that constitutes a "Application Layer
    Attack". Is it an attack *against* the application layer, or is it an
    attack *transmitted* over the application layer against a host system.

    I'm inclined to disagree with your assessment and boldly proclaim that a
    BIND buffer overflow is not an application layer attack. Yes, it's an
    attack against the application, but it is executed over the network
    layer.

    I believe "application layer attacks" should be those that get
    transmitted via application protocols. The already mentioned example of
    SQL injection falls within that category.

    But everyone sets their own metrics and definitions these days anyway.
    According to some vendors, attacks don't even exist. :)

    Cheers,
    Frank

    
    

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



  • Next message: Paul D. Robertson: "Re: [fw-wiz] Multiple firewalls from different manufactureres"

    Relevant Pages

    • Re: 802.11i ?
      ... > You really think you can keep me from doing a layer 2 attack? ... My wireless connection is not my entire network. ... While you may be ab le to create a DOS attack, it won't give you access to ...
      (alt.os.linux.suse)
    • RE: On classifying attacks
      ... Remote -- control/access of resources occurs from outside the ... Using this definition the email example is local and both bind examples ... The bind vulnerabilities are completely solved by ... But it is a remote *attack*. ...
      (Bugtraq)
    • BIND 8 EOL and BIND 8 DNS Cache Poisoning (Amit Klein, Trusteer)
      ... BIND 8 EOL and BIND 8 DNS Cache Poisoning ... this is a different attack from BIND 9 DNS cache poisoning. ... BIND 8 caching DNS server and force users who use this DNS server to ...
      (Bugtraq)
    • RE: CAIS-ALERT: Vulnerability in the sending requests control of BIND
      ... I know this attack methodology. ... This attack is the simplest and most widely used attack to do DNS Spoofing ... in the bind 8.3.4,4.9.11 and older bind, and I can prove THIS. ... The success probability in my attack methodology to implement of DNS ...
      (Bugtraq)
    • Re: [Q] How to make [warlock) demon attack target
      ... >> voidwalker are passive and don't attack until the mob hits me. ... >I like to make a macro that makes my pet attack and casts a dot, and bind it ... let me bind a key for Seduction, or Suffering, or Spell Lock. ...
      (alt.games.warcraft)