11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 15: Securing Your Network 407CountermeasuresYou can use ingress <strong>and</strong> egress filtering on perimeter routers.Session HijackingWith session hijacking, also known as man in the middle attacks, the attacker uses anapplication that masquerades as either the client or the server. This results in eitherthe server or the client being tricked into thinking that the upstream host is thelegitimate host. However, the upstream host is actually an attacker’s host that ismanipulating the network so that it appears to be the desired destination. Sessionhijacking can be used to obtain logon information that can then be used to gain accessto a system or to confidential information.VulnerabilitiesCommon vulnerabilities that make your network susceptible to session hijackinginclude:● Weak physical security● The inherent insecurity of the TCP/IP protocol suite● Unencrypted communicationAttacksAn attacker can use several tools to combine spoofing, routing changes, <strong>and</strong> packetmanipulation.CountermeasuresCountermeasures include the following:● Session encryption● Stateful inspection at the firewallDenial of ServiceA denial of service attack is the act of denying legitimate users access to a server orservices. Network-layer denial of service attacks usually try to deny service byflooding the network with traffic, which consumes the available b<strong>and</strong>width <strong>and</strong>resources.VulnerabilitiesVulnerabilities that increase the opportunities for denial of service include:● The inherent insecurity of the TCP/IP protocol suite● Weak router <strong>and</strong> switch configuration● Unencrypted communication● Service software bugs

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!