RE: AltaVista_Traversal attack from mod-pubsub.org?
"Ben Sittler" <[email protected]> Mon, 6 Oct 2003 14:18:38 -0700
| Newsgroups | gmane.comp.web.mod-pubsub.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Mike, I may misunderstand, but I believe the "spurious" request is not actually coming back to the client IP -- rather the firewall is detecting this in the *outgoing* direction, as part of a hidden form submission (or other client library request.) If you have reason to believe mod-pubsub.org is opening sockets into your client machine, do let us know the details! The python pubsub server (at the moment the only pubsub server really in use at mod-pubsub.org) *should be* incapable of opening an outbound socket connection -- it relies entirely on client-initiated sockets for all communication. Looking forward to more details... -Ben -----Original Message----- From: S. Mike Dierken [mailto:[email protected]] Sent: Sun 10/5/2003 5:58 PM To: Ben Sittler; Adam Rifkin Cc: [email protected] Subject: Re: [Mod-pubsub-developer] AltaVista_Traversal attack from mod-pubsub.org? I don't know if ".." is supported in URI, but form data should be okay. Either one is fine by me, I'm just curious why a request would come back to the client IP address? ----- Original Message ----- From: "Ben Sittler" <[email protected]> To: "S. Mike Dierken" <[email protected]>; "Adam Rifkin" <[email protected]> Cc: <[email protected]> Sent: Sunday, October 05, 2003 4:43 PM Subject: RE: [Mod-pubsub-developer] AltaVista_Traversal attack from mod-pubsub.org? Apparently this means we sometimes submit form data with "../" in it. I regard this as correct behavior (we don't use that to circumvent security,) and see no reason to change our data format to work around this particularly harmful firewall heuristic. Your thoughts? -Ben -----Original Message----- From: [email protected] on behalf of S. Mike Dierken Sent: Sat 10/4/2003 9:20 PM To: Adam Rifkin Cc: [email protected] Subject: [Mod-pubsub-developer] AltaVista_Traversal attack from mod-pubsub.org? I'm seeing Norton Internet Firewall detect an attack sourced at mod-pubsub.org whenever I connect to the chat server there. It claims an attack similar to the AltaVista_Traversal is ocurring. Different incoming ports are reported. Does anybody know what this means? ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Mod-pubsub-developer mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-pubsub-developer ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf