RE: [VulnDiscuss] Re: Preventing exploitation with rebasing
"Nick Iglehart" <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq,gmane.comp.security.ntbugtraq |
|---|---|
| Organization | System Security Solutions |
| Message-ID | <001101c2cc65$d9fcc5e0$2365a8c0@LAPTOP> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Anyone who only implements one security method is bound to fail anyways. I think the point of this is to prevent script kiddie attacks and give administrators a chance to respond to more determined attackers. If someone is sending 1000's of packets at a particular service it is bound to be noticed whether it is a new exploit or not. If the admin has not managed to detect the attack and take action on it by the time an attacker has brute force the address then they are not going to have the knowledge to rebase anyways. I think it is a good idea that, albeit not a necessarily new one, that needs more investigation. Even though it's not new, it has not been thoroughly discussed and I think it should be. >Dear David ! > >With all the respect... I think your ideea is a BAD one ! Why ? >Well... It might be verry efective if one to... mhm... 100 persons >would aply this technique. That's because hackers/worms wouldn't >mind loosing a few servers if they got the rest of the world. But >if this technique would became a standard then the worm-industry >(if there is such a thing) would also evolve... making it >brute-force the addreses. -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com> iQA/AwUBPj/ic6q/UK5/FuEgEQLITQCfSQfRkuX63UWDbN699Mi2yYmdUpYAoOug dqOMErTMYmYRveEjX+IK6mj5 =0MrM -----END PGP SIGNATURE----- --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.445 / Virus Database: 250 - Release Date: 1/21/2003