> I still reckon it does, I believe you can't or its difficult to fake those
> values (but I could be wrong) i.e. IP address and xhttp_forwarded_for.

You can fake those values. For HTTP stuff I can change any headers just
using Firebird & the LiveHTTPHeaders plugin.

For lower level (TCP/IP) check out http://www.grc.com/dos/grcdos.htm, the
section titled 'An Attack Prone to Filtering?' covers spoofing network
information.

I guess what I am saying is that someone can send you any information they
like from the ground up - and so you can't trust any of it.

OT: Read the whole article for a bit of a jolt to the system. The IRC
dialogue with <^b0ss^> is especially fun. This was an attack by a 13 year
old against servers run by a security expert.

OK I'm off home, but before I go - I'm not a security expert by any means &
there a probably people on this list who can provide much better information
or correct me where I've stuff up. If you can, please do.


Cheers

Mark


------------------
Mark Stanton
Technical Director
Gruden Pty Ltd
Tel: 9956 6388
Mob: 0410 458 201
Fax: 9956 8433
http://www.gruden.com


---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia
http://www.mxdu.com/ + 24-25 February, 2004

Reply via email to