Beefy Boxes and Bandwidth Generously Provided by pair Networks
No such thing as a small change

RE (tilly) 2: Warning our Fellow Monks

by tilly (Archbishop)
on Oct 11, 2000 at 01:08 UTC ( #36130=note: print w/replies, xml ) Need Help??

in reply to RE: Warning our Fellow Monks
in thread Warning our Fellow Monks

You are not protected. That parameter is a standard thing to try, along with various variations of it. You may need to vary the number of ..'s, you may need to fool an RE or two, but there are a finite number of combinations to use, and eventually you will hit one.

You see there are a limited number of basic attacks the attacker will be trying to get to happen. There are a collection of ways to fool standard code with standard mistakes into falling for something interesting. And your code has a set of input parameters. So the script kiddie is going to list your parameters, and then plug a series of inputs in, until something interesting happens, and this attack will be on the list of obvious things to try.

Were your code written in C an attacker could similarly pass longer and longer parameters until they got evidence something crashed. Once it crashes then you play around figuring out at what length it crashes. Once you know that then you start putting interesting exploits at that position. Again, it takes virtually no knowledge of the specifics of the code to figure out how to abuse it. Perl is virtually immune to buffer overflows, but they make up the most commonly reported security errors.

And that is the key. Identify an easy to make mistake, start trying it out in random places. Eventually you find a way in. The key is not to analyze any one target in depth and break in there, rather it is to rattle a lot of doors until one falls apart. And once you break one door, probably lots more have the same flaw...

Another fun one is default passwords. For instance Microsoft's SQL Server had a default login for the longest time. It has been fixed for a year now, but plenty of sites still have the login. So go, try that key on enough sites, and eventually you will get a database of credit cards.

It is as easy as that!

Really. :-(

Replies are listed 'Best First'.
RE: RE (tilly) 2: Warning our Fellow Monks
by Adam (Vicar) on Oct 11, 2000 at 02:55 UTC
    Ding Ding Ding. And the always verbose tilly comes in with the answer I was looking for: Dumb Luck

    The malicious hacker does not need to know your code to abuse it. Some kid who knows LWP and has plenty of time on hand can easilly write a simple little script to go through a handful of different attacks on a list of sites that the kid has visited recently. Ooops... there goes your day. ++ for tilly

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://36130]
and all is quiet...

How do I use this? | Other CB clients
Other Users?
Others examining the Monastery: (7)
As of 2017-02-22 13:38 GMT
Find Nodes?
    Voting Booth?
    Before electricity was invented, what was the Electric Eel called?

    Results (327 votes). Check out past polls.