Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

Re: Script Based Attacks & Form Hacks

Subject: Re: Script Based Attacks & Form Hacks
Date: Fri, 22 Jul 2005 07:36:50 -0700
it does not present an insurmountable hurdle since there is nothing
in the system that can't be automated.
It would be relatively simple for an attacker to control an email
server(s) and therefore to be able to automate the process of parsing
and responding to predictable emails.

Indeed. I agree with you. I have written a procmail script that can
respond to a verification/validation email automatically. The
techniques i mentioned are to just deter casual script kiddies.  I
agree with the Paul's suggestion to use CAPTCHA for prevent against
more serious attacks. But then again even CAPTCHA image can be
decyphered.

Basing a defense on the IP address of the submitter is also not
really reliable because of the relative ease with which an attacker
can use proxies to submit requests (http://proxy.org/lists.shtml).

However the list of proxy servers is also limited :)

-- 
In Peace,
Saqib Ali
http://www.xml-dev.com/blog/

<Prev in Thread] Current Thread [Next in Thread>