Re: [fw-wiz] Application-level Attacks

From: Devdas Bhagat (devdas_at_dvb.homelinux.org)
Date: 02/12/05

  • Next message: Tina Bird: "RE: [fw-wiz] VPNmadness gets more support;"
    To: firewall-wizards@honor.icsalabs.com
    Date: Sat, 12 Feb 2005 08:50:56 +0530
    
    

    On 09/02/05 00:54 +0100, gmx wrote:
    > Hello
    >
    > Well... i dont think that application level atacks have something to
    > do with ports... simply because i think, ports are at tcp-layer, and
    > if you talk about application, you talk about layer 7... if i hear
    > application layer and attacks, all i can imagine is virii...

    No. The biggest attacks which I can recall not beingat the application
    layer were the ATH0+++ which disconnected dialup users, and the ping of
    death which exploited a hole in the Windows network stack.

    > Well, i dont know any other atack for layer 7 than malicious code.

    These atacks are all malicious code, and include worms, viruses,
    trojans, and are rather applicable across operating systems and
    applications.

    > Means, all you can do at this layer, is to use an antivirus software,
    > imho.
    > Please correct me if i could be worng.

    Or run secure code in the first place. Patching helps as well.

    Devdas Bhagat
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Tina Bird: "RE: [fw-wiz] VPNmadness gets more support;"

    Relevant Pages

    • Re[2]: [fw-wiz] Application-level Attacks
      ... i dont think that application level atacks have something to ... do with ports... ... application layer and attacks, all i can imagine is virii... ...
      (Firewall-Wizards)
    • RE: Use of Taps for IDS
      ... this is a layer 1 (physical ... Note that this usually requires all the ports to be of a single ... of each connected machine whenever a frame is sent. ... the switch typically floods ALL ports with the ...
      (Focus-IDS)
    • Re: 2000 server solution
      ... > layer model and on which layer the filtering done by the device takes ... > Give me a reason to hide something, that is designed for public access. ... If nothing is listerning on the other ports there is no reason to ...
      (comp.security.firewalls)
    • Re: bittorrent slow
      ... it's a layer 3 limiter which can be evaded by shifting ... evaded by shifting ports, and may or may not be evaded by encrypted ...
      (Fedora)
    • Odp: wan lan ports in routers
      ... >> So, can I say that LAN ports work in the same TCP layer, and LAN and WAN ... can't route packets from various subnets and WAN on 3rd-layer so it can do ...
      (comp.os.linux.networking)