[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

RE: Can A Web Site Be Reliably Defended Against DoS Att acks?

  • To: "Alaric B Snell" <alaric@a...>
  • Subject: RE: Can A Web Site Be Reliably Defended Against DoS Att acks?
  • From: "Dare Obasanjo" <dareo@m...>
  • Date: Wed, 4 Feb 2004 13:25:44 -0800
  • Cc: "Rich Salz" <rsalz@d...>,"Bullard, Claude L \(Len\)" <clbullar@i...>,<jcowan@r...>,<xml-dev@l...>
  • Thread-index: AcPrZBzhkEJdhrbzQY6mocJ9s7pbVgAAIQzt
  • Thread-topic: Can A Web Site Be Reliably Defended Against DoS Att acks?

dos att
That solution basically amounts to creating a user hostile system where users can't run applications unless allowed to by the system administrator. As for the home user, I don't see how this ultra-cumbersome approach would even get off the ground let alone fly with the average IMing, music downloading teenager. Even if you did all that they'd just go through all the steps and launch the application. 
 
How many people would have believed that requiring a user to download a zip file, unzip it's contents then launch the contained executable would be a virus vector that would actually work let alone be one of the fastest spreading of all time? 
 
-- 
PITHY WORDS OF WISDOM
Blessed are the meek for they shall inherit the Earth, minus 40% inheritance tax. 

________________________________

From: Alaric B Snell [mailto:alaric@a...]
Sent: Wed 2/4/2004 1:15 PM
To: Dare Obasanjo
Cc: Rich Salz; Bullard, Claude L (Len); jcowan@r...; xml-dev@l...
Subject: Re:  Can A Web Site Be Reliably Defended Against DoS Att acks?



Dare Obasanjo wrote:
> Short of creating a mail client and server that prevented people from
> receiving mail attachments, how would you solve the problem exploited
> by this current virus on any one of the popular operating systems
> existing today?

On many UNIX systems, just mount /home as not allowing execution, so
people need root priveleges to install software, and non-installed
software can't be run.

UNIX systems don't really have this concept of an executable file
sitting there waiting to be clicked on, anyway - things generally need
to be in your path to get executed to begin with. If I got sent an
executable file as an attachment, I'd need to save it to my home
directory then open up a shell window and explicitly invoke it, with a
"./" prefix to override the path and execute a file from the current
directory.

ABS




PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.