> I still reckon it does, I believe you can't or its difficult to fake those > values (but I could be wrong) i.e. IP address and xhttp_forwarded_for.
You can fake those values. For HTTP stuff I can change any headers just using Firebird & the LiveHTTPHeaders plugin. For lower level (TCP/IP) check out http://www.grc.com/dos/grcdos.htm, the section titled 'An Attack Prone to Filtering?' covers spoofing network information. I guess what I am saying is that someone can send you any information they like from the ground up - and so you can't trust any of it. OT: Read the whole article for a bit of a jolt to the system. The IRC dialogue with <^b0ss^> is especially fun. This was an attack by a 13 year old against servers run by a security expert. OK I'm off home, but before I go - I'm not a security expert by any means & there a probably people on this list who can provide much better information or correct me where I've stuff up. If you can, please do. Cheers Mark ------------------ Mark Stanton Technical Director Gruden Pty Ltd Tel: 9956 6388 Mob: 0410 458 201 Fax: 9956 8433 http://www.gruden.com --- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia http://www.mxdu.com/ + 24-25 February, 2004
