Re: Basic authentication against automated attacks



"Bulent" <bulent@xxxxxxxxxxxxxx> wrote in message
news:1141099831.090526.260730@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
: Ken,
:
: Thank you for your quick response.
:
: I assume that a much greater number of components would be involved
: "after" the authentication process. If this assumption is correct, is
: it fair to say that basic authentication (with SSL) would minimise the
: risk of such attacks (buffer overflow) being successful.

Yes. Anything that prevents the payload from getting to the vulnerable
component would help.

So, requiring SSL would stop any attack that only operated over HTTP
Using Host-Headers would stop any attack that didn't supply a Host: HTTP
header
Using Basic Auth (or any Auth) would stop attacks that couldn't supply a
username/password

All of this does assume that the affected component is after the barrier.

Mostly this will stop automated attacks - manual attacks are a different
matter (but generally manual attacks would be directed against valuable
servers, not a server you might have sitting at home running your personal
website).

Cheers
Ken


.



Relevant Pages

  • Re: Basic authentication against automated attacks
    ... "after" the authentication process. ... risk of such attacks (buffer overflow) being successful. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Changes in IDS Companies?
    ... Things like port scans and DoS attacks very often ... >> If people are running insecure web servers, ... when people don't update their patches at ... > downplay the vulnerability to save face, so admins even if they are trying ...
    (Focus-IDS)
  • RE: Hacking to Xp box
    ... If the firewall doesn't block ICMP, ... you need to find some vulnerability that could be exploited to run ... > restricts most of the attacks that use anonymous connections. ... > login pages, dynamic content etc. Firewalls, SSL and locked-down servers ...
    (Pen-Test)
  • Re: Blocking attacks from spoofed IP addresses
    ... cause a _Self_ Denial Of Service attack. ... Defeating Denial of Service Attacks ... of our DMZ servers, and had source IPs from our public DNS servers. ... Web services are on your port 80 and/or 443, ...
    (comp.os.linux.networking)
  • RE: Changes in IDS Companies?
    ... In any ID implementation tuning of the device to reduce false alarms is ... necessary flexibility to drop some user specified attacks while only ... >> Pretty sad state of affairs, when people don't update their patches at ... >>> only lazy admins get their servers broken into), ...
    (Focus-IDS)