It would be cool if we (people, programmers, anyone!) could work on a secure (or much 
securer) process, i.e. describe the current process - have it torn to pieces like you 
just did and then fix it...

Hmm I tried that a while ago, not many people interested in security - well, to talk 
about it openly anyway...

Taco Fleur
07 3535 5072
Blog: http://www.tacofleur.com/index/blog/
Methodology: http://www.tacofleur.com/index/methodology/
Tell me and I will forget
Show me and I will remember
Teach me and I will learn


-----Original Message-----
From: Mark Stanton [mailto:[EMAIL PROTECTED]
Sent: Wednesday, 21 January 2004 9:06 AM
To: CFAussie Mailing List
Subject: [cfaussie] RE: Old Post RE: Browser Sessions - elaborate


> I am not debating whether you can't fake IP headers, I don't know - what I
> do wonder is, if you fake IP headers, and you specify an IP
> that's not you,
> then how are you going to receive data back? If you know what I mean?

True, but you don't need to get data back to the client to cause damage.
Think of an online banking app - if I know the exact steps required to
transfer money from one account to another - why do I need a response from
the server at all?


Cheers

Mark


------------------
Mark Stanton
Technical Director
Gruden Pty Ltd
Tel: 9956 6388
Mob: 0410 458 201
Fax: 9956 8433
http://www.gruden.com


---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia
http://www.mxdu.com/ + 24-25 February, 2004

---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia
http://www.mxdu.com/ + 24-25 February, 2004

Reply via email to