Re: [fw-wiz] Application-level Attacks

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 01/29/05

  • Next message: Marcus J. Ranum: "Re: [fw-wiz] Application-level Attacks"
    To: "Marcus J. Ranum" <mjr@ranum.com>
    Date: Sat, 29 Jan 2005 10:43:00 -0500 (EST)
    
    

    On Sat, 29 Jan 2005, Marcus J. Ranum wrote:

    > Paul D. Robertson wrote:
    > >Hmmm, but an SQL injection attack isn't really a protocol issue- it's an
    > >unexpected input issue-
    >
    > It's an application-specific flaw in the application accepting the input,
    > unless I really misunderstand how SQL injection works.
    >
    > If the thing that is broken is an "application" then attacks against
    > that break are "application attacks" no?

    yep, sorry- it looked like you lumped it in with "protocol" and it's
    really a different kettle of fish in my book...

    Maybe it's time to revisit the whole attack taxonomy thing again...

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Marcus J. Ranum: "Re: [fw-wiz] Application-level Attacks"

    Relevant Pages

    • Re: [fw-wiz] An article from Peter Tippett/TruSecure...
      ... On Mon, 10 Mar 2003, Paul D. Robertson wrote: ... that defense in depth 1) buys the organization time in dealing with new ... For many companies, accepting Darren Reed's ... costs of maintenance slightly. ...
      (Firewall-Wizards)
    • Re: 16 out of 17 bishops will ignore evidence of gay relationships
      ... > Come on, now, Paul. ... Fair enough - but you haven't addressed my suggestion (which may be ... pertinent) that people might misunderstand you because you can be quite ...
      (uk.religion.christian)
    • Re: Can Christians be magistrates?
      ... We've been so concerned with how far Grayling may misunderstand RC ... teaching and its effects that we've ignored Paul Grieg's question, ...
      (uk.religion.christian)
    • Re: more power to their elbow
      ... Brimstone wrote: ... > PC Paul wrote: ... >> misunderstand something in order to see who will bite? ...
      (uk.rec.driving)
    • Re: Tipsters Cap 3N - Game 2 Result
      ... >> Results from Game 2 ... >> In order to make the scoring fair over the course of the 3N, ... From: Paul Kendall ... > I will only be accepting tips from this thread. ...
      (rec.sport.rugby.union)