“Attackers are smart, you are not.” is a bad message
Dave G. | September 19th, 2006 | Filed Under: Uncategorized
Today I attended the Secure Software Forum’s Workshop in midtown manhattan. I would say it wasn’t particularly interesting for people who understand this stuff. They did the standard show us all the bad things:
- Cardsystems, Guidance and Rhode Island compromises to ‘set the scene’.
- Cross Site Scripting. Exactly what you think this is. Lots of time showing all the clever ways you can get lots of clever HTML/Javascript into someone’s browser.
- SQL Injection. Also exactly what you would expect. Lots of time showing all the clever SQL you can execute.
- Forced Browsing. and so on…
Lots. Lots. Lots. I think one of the bad things about this space is the amount of time we spend talking about all of the bad things that can happen as opposed to how a few things can prevent you from all of them. We show how clever attackers are. We basically set people up to think that they can’t really stop these attacks. And when you set up the problem as untenable, you reduce the likelihood that people will really try.
I did like the speaker’s approach to web app security. He distinguished between input validation (this happens first) and safe data handling (this happens second when it does happen). It is worth mentioning, because a lot of people write an input validation component and rely on it as an exclusive means of managing security.
It is kind of amazing that nothing has really changed in web application security over the course of a couple of years. And by amazing, I mean sad. A lot of this seemed new to the audience, who were all security or developer types.
My question is, why aren’t web application firewalls as commonly deployed as traditional firewalls?


Add New Comment
Viewing 7 Comments
Thanks. Your comment is awaiting approval by a moderator.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Add New Comment
Trackbacks