Network Security

ICMP Destination UnreachableFragmentation Needed but DF Bit Set

ICMP destination unreachable messages (type 3 code 015) are a whole range of messages designed to alert the sending system that something is wrong with a particular message sent. This includes specific errors such as network unreachable (code 0), host unreachable (code 1), protocol unreachable (code 2), and port unreachable (code 3). These types of messages are generated by hosts and routers when a sending system tries to go somewhere that is unreachable for whatever reason. Many security...

Data Scavenging

Table 3-2 shows the summary information for the data-scavenging attack. Network utilities Whois, Nslookup, Finger, Traceroute, Ping Learn IP ranges, DNS servers, mail servers, public systems, points of contact, and so forth Data scavenging is generally step 1 in any deliberate attack against a network. Here, the attacker uses a combination of network-based utilities and Internet search engine queries to learn as much as possible about the target company. The attack is almost impossible to...

Figure 311 Smurf Attack

Network Smurf Tool 1990 Full

At the bottom of Figure 3-11 you can see the attacker sending an ICMP echo request packet to the broadcast address of the bounce network. The bounce network is not the actual attack target, though it often experiences an indirect denial of service effect as a result. The ICMP packet has a spoofed source address from a device on the victim network (typically a router interface). The smurf attack is a type of amplification attack because when the single spoofed broadcast ping arrives at the...

Network Manipulation

Table 3-7 shows the summary information for the network manipulation attack. Firewall application security cryptography The most common network manipulation attack is IP fragmentation. Here the attacker intentionally fragments traffic in an effort to bypass a security control, which could be network based (IDS or firewall) or application based. One tool used to launch an IP fragmentation attack is called Fragroute. More information about Fragroute is available at http monkey.org dugsong...

Fragmentation and Path Maximum Transmission Unit Discovery

As you learned in Chapter 6, General Design Considerations, fragmentation can be dealt with by allow code 4 messages into your network. This allows a function called path MTU discovery (PMTUD) to functi segments. End-host-to-end-host MTU negotiation occurs at the beginning of a TCP communication with the TCP header. This doesn't take into account differences in the path MTU, though, as introduced by di This is where PMTUD is useful. It is helpful to first see a basic example of fragmentation...

Domains of Trust

Within all networks, there are devices with differing levels of value and differing levels of attack susceptibility. This concept is discussed in Chapter 2, Security Policy and Operations Life Cycle. By combining these factors, you can start to define the relative attention needed for a given information asset. In a flat network, as shown in Figure 12-7, the security of these assets is left completely up to the applications. As you can see, there is no segmentation except where necessary (WAN...

The Difficulties of Secure Networking

Considering that we as a community have been working at this problem for many, many years, understanding some of the reasons why we still don't have completely secure networks is useful. Security is not as simple as flipping the secure switch on a device, and it might never be. There are many reasons for this, and perhaps the most significant reasons have nothing to do with the technology directly. The following paragraphs outline the reasons that pertain directly to the topics in this book....

Host Based Firewalls

Table 4-10 shows the summary information for host-based firewalls. Direct access Remote control software Host-based firewalls are also commonly called personal firewalls when run on a client PC. They are exactly what their name describes a firewall running on a host configured to protect only the host. Many host-based firewalls offer IDS in the form of rudimentary application checks for the system they are configured to protect. Trying to maintain these firewalls on all client PCs or even just...

MAC Flooding

Table 3-16 shows the summary information for the MAC flooding attack. Fill a switch's CAM table and then sniff the legitimate traffic that floods as a result MAC flooding refers to sending packets with spoofed source and destination MAC addresses from the attacker's system to the Ethernet network. The CAM table, which keeps track of MAC address locations on a switch, has a limited size. If that table is filled, frames destined to MAC addresses without a CAM entry are flooded on the local VLAN...

Homogeneous and Heterogeneous Networks

There is an interesting dichotomy with respect to network security and network diversity. That is, homogeneous networks are easier to manage and configure, making them good for your organization's security in some ways. In other ways, they are bad because they offer a single point of compromise for a given piece of your IT infrastructure. The best example is in the area of desktop systems. Today, the vast majority of organizations have standardized on Microsoft application and operating system...

Three Tier Web Design

Cisco Three Tiered Network Design

Once your organization gets serious about e-commerce, you should probably think about a dedicated three-tier design to accommodate the security requirements of the sensitive data that is entrusted to you by your customers. This design basically separates the application and database servers, which were combined on a single platform in the two-tier design. Many financial organizations adopt a three-tier design, as do businesses with large e-commerce presences. This design generally is separate...

General Best Practices and Route Summarization

The basic best practices for IP addressing should be familiar to you. At a high level in your design, you first must decide whether the IP address of the user on your network will have any significance from a security standpoint. For example, if you are an organization with three sites, are you just going to assig a subnet to each of the three sites, even though there are individuals at each site with different levels o security access This approach is fine if your security system depends...

Private VLANs

PVLANs offer further subdivision within an existing VLAN, allowing individual ports to be separated from others while still sharing the same IP subnet. This allows separation between devices to occur without requiring a separate IP subnet for each device (and the associated IP addresses that would waste). In it simplest form, PVLANs support isolated ports and promiscuous ports. Isolated ports can talk only to promiscuous ports, while promiscuous ports can talk to any port. In this deployment,...

Ha Gre Hub and Spoke

Figure 10-31 shows the topology for an HA GRE hub-and-spoke design. Note that the GRE tunnel IP addresses are not shown to avoid cluttering the diagram. They are defined in the same manner as the previous design. Figure 10-31. HA GRE Hub-and-Spoke Design Figure 10-31. HA GRE Hub-and-Spoke Design Here you can see that R10 has a primary tunnel to R50 and a secondary tunnel to R40. R20 is configure just the opposite. Bandwidth metrics are placed on the GRE links to specify path preference. Since...

Nonroutable Networks

Besides private network addressing and antispoof filtering, there are a host of other networks that have no business being seen, including those that won't be seen for some time because they haven't yet beei allocated. For example, at the time this was written, the 8 networks from 82 to 126 had not yet been allocated from the Internet Assigned Numbers Authority (IANA) to any of the regional Internet registrie (RIRs). This data can be tracked at a very high level at the following URL IANA is...

Backscatter DDoS Trace Back

This technique was developed by Chris Morrow and Brian Gemberling at UUNET, and it allows a DDoS attack to be stopped and trace back to occur in approximately 10 minutes. The following site provides more information http www.secsup.org Tracking . At a high level, the mitigation technique works by combining aspects of the sinkhole and black hole routing discussed previously. When a system is under attack, the black hole routing technique allows IS edge routers to route the traffic to null0. This...

N Squared Problem

Here's how the math for the n squared problem works assume you have two parties connecting to one another. The formula for the n squared problem says that for each party n, the number of connections needed can be determined by the formula n * (n 1). So, for two parties, you need two connections (one in each direction). If you only want to know how many bidirectional connections you need, just divide your result by 2. So, for a 100-peer fully meshed VPN connection using preshared keys, you have...

War Dialing and War Driving

Table 3-4 shows the summary information for the war dialing driving attack. War dialers many options Tone Loc is popular War driving Netstumbler (http www.netstumbler.com ) Find insecure modems or wireless APs connected to a victim network regular checking using war-driving tools War dialing and war driving allow attackers to get into the victim network without going through the front door. In war dialing, the attacker dials the phone number prefixes assigned to the victim or the victim's area,...

Threats and Attack Mitigation

The technologies to mitigate the threats in an OOB network are slightly adjusted from the previous designs. In addition to the techniques described for the other management designs, a new concern must be dealt with keeping the OOB network and the management network separate. There are several ways to achieve this Separate address space By using separate address space for the management network, you can make it easy to filter production traffic from the management network and vice versa. An easy...

Table 319 Tcp Syn Flooding

Overwhelm a specific host with connection requests IDS, log analysis, and application security TCP SYN flood attacks are one of the earliest forms of flooding attacks. Kevin Mitnick used a form of TCP SYN flooding in his famous attack against Tsutomu Shimomura's computers. The attack works by sending a TCP SYN packet (the first packet of the TCP three-way handshake) and then never acknowledging the SYN-ACK that is sent in response. Because TCP is somewhat reliable, the server that received the...

TCP Intercept

TCP Intercept is a network-level protection for SYN floods. It works by brokering (on the device running TCP Intercept) a connection to a server on behalf of the client. If an incoming connection never establishes itself, the client is not affected. When the connection does establish, the device running TCP intercept passes the communication on to the real server transparently. The Cisco PIX documentation does a good job of describing the feature in detail, so I've included it here. An...

CAR Design Considerations

One of the first tasks in successfully configuring CAR is determining what normal traffic loads are. One c the easiest ways to do this is to start your CAR policy by setting your conform action to transmit and yo exceed action to transmit. This command for the previous ICMP example looks like this Router(config-if) rate-limit output access-group 102 100000 8000 8000 conform-action transmit exceed-action transmit In this way, no traffic is dropped, but the CAR process is still running. You can...

Table 31 Probing and Scanning Example

Nmap (http www.insecure.org nmap) Nessus (http www.nessus.org) Learn IPs and applications available at victim network IDS and firewalls (with log analysis) The following list defines the components of the table Member of class subclass Refers to the class and subclass to which the specific attack belongs. In Figure 3-4, for example, the attack TCP spoofing is a member of the class spoof and the subclass transport. Sample implementations Provides examples of the given attack. In some cases, this...

ARP Considerations

ARP is designed to map IP addresses to MAC addresses. It was also, like most protocols still used in IP networking today, designed at a time when everyone on a network was supposed to be reasonably trustworthy. As a result, the protocol is designed around efficiently executing its task, with no provisions for dealing with malicious use. At a basic level, the protocol works by broadcasting a packet requesting MAC address that owns a particular IP address. All devices on a LAN will see the...

Table 38 Buffer Overflow

Critical application vulnerabilities check http www.cert.org for the latest Escalate privileges on target machine Buffer overflows are the most common form of application vulnerability. In short, they occur when an application developer fails to do proper bounds checking with the memory addresses an application utilizes. For example, a typical program might expect 20 bytes of input from the user for a particular memory address. If the user instead sends 300 bytes, the application should drop...

Asymmetric Routing and State Aware Security Technology

As networks increase in size, so do the chances that they have asymmetric traffic somewhere within them. Asymmetric traffic is traffic that uses a different path for its return than the original path of the request. The topology in Figure 6-21 shows a representative network with several places where asymmetric traffic can occur. Traffic between the user PC and either the finance server or the WWW server can flow in an asymmetric manner at several points along the network. Between the PC and the...

Stateful Firewall DMZ Design

Firewall Desgin

After stateful firewalls became more generally available, organizations started replacing the second router in the dual-router DMZ design with a stateful firewall. This design is shown in Figure 7-5. Figure 7-5. Stateful Firewall DMZ Design Figure 7-5. Stateful Firewall DMZ Design This design improves on the dual-router DMZ design by allowing strong filtering between the internal network and the public servers and Internet. Many organizations still use this filtering option today, especially...

Stateful Versus Stateless ACLs and L3 Versus L4 Filtering

The campus network usually doesn't have clean-cut notions of trust like the edge does. As you learned in Chapter 12, Designing Your Security System, it is easy to call the Internet untrusted and your data center in your campus trusted. There is a smaller gradient of trust between the data centers, user communities, and department-specific subnets, though. In Chapter 12 you learned that a smaller gradient of trust between two zones allows the security controls at the choke point between the...

XEAP Protocol Details

The protocol works in conjunction with a proposed standard defined in RFC 2284, PPP Extensible Authe Protocol (EAP). EAP provides a framework for multiple authentication types to occur using the same m< format. The three main components in an 802.1x exchange are as follows Supplicant The client system connecting to the network Authenticator The Ethernet switch or other device to which the supplicant is attempting to conne Authentication server The server that houses the identity information...

Figure SS Single Local DNS Server

Are Dhcp And Dns Internel Servers

The firewall access control policies to implement this design are as follows. Only the DNS-related portior of the ACL are shown. Bogon and ingress filtering are excluded for clarity. These ACLs assume that the remote DNS server is a slave as opposed to another master. This means the slave can update by zone transfers. If the slave were a master, you would need to determine another way to synchronize the data IPermit the DNS Queries from Internal hosts to the DNS server access-list 101 permit...

Strive for Operational Simplicity

Network designers make decisions regarding operational complexity every day. Most don't call it that, though they tend to think along the lines of the difficulty and burden that specific technology places on administrators or users. This section gets to a key aspect of your network security system achieving operational simplicity can mean the difference between a security system that works for you and a security system that you work for. Some hard and soft metrics to measure your system include...

Appendix C Sample Security Policies

To give you a flavor of security policy wording and scope, this appendix includes three sample security policies in use by an organization. For more information on security policies, refer to Chapter 2, Security Policies and Operations Life Cycle. For more sample policies, check out the SANS security policy website at the following URL Here is one company's acceptable use policy. Notice that even though this is the most essential security policy you will write, this one is relatively short....

Routers with Layer 34 Stateless ACLs

Table 4-14 shows the summary information for routers with Layer 3 4 stateless ACLs. Table 4-14. Routers with Layer 3 4 Stateless ACLs Table 4-14. Routers with Layer 3 4 Stateless ACLs Router with Layer 3 4 stateless ACLs Direct access Network manipulation IP spoofing IP redirect Routers with basic stateless ACLs are workhorses in network security. They deserve the name firewall just as much as a stateful appliance firewall does, even though they might lack certain features. Basic ACLs, shown...

Ethernet Switch Wtk

The key security techniques configured on the Ethernet switch are as follows Network device hardening This device should have its configuration hardened per the best practices in Chapter 5. L2 control protocol best practices All Ethernet switches in these designs should account for the L2 control protocol best practices discussed in Chapter 6. This includes, at a minimum, setting STP BPDU Guard on all PC ports to prevent accidental or deliberate spanning tree problems. Simply disabling spanning...

ICMP Echo Request and ICMP Echo Reply

Icmp With Example

ICMP echo request (Type 8 Code 0) and ICMP echo reply (Type 0 Code 0) are better known as the message types used by the ping command. The format of an ICMP echo message has the standard 8 bytes of ICMP header information and then allows for a variable-length data field that can contain any kind of data. Certain size ping packets caused system crashes on some older OSs. This attack was commonly called the Ping of Death. More information can be found here Permitting ICMP echo can lead to DoS...

Figure 35 Ethereal in Action

Cilt. fill T.< .Mrr i di v ritiv Cilt. fill T.< .Mrr i di v ritiv Smi l nrfcfl- 383 9 tf3 N > t i ucncr rtjibtr 38LB3E0L fcJtrovLedaevcnt rUbw 561f ffil2 Htxfcr njlh iO tyt SFlijs KCO10 P H, mO Uhrriov is L ES J Chcik-i O'dSiF cWrrcO Fttsr i 2 bjtsi) 0 ferstr lAEUf h-otowl KA+f 15 jjtjr Lm MIJ IS Ogt T f J PEH ItatUtt (1 V -iiwij I fly t tlMt If KV idmuFltr l G.lii.KW.i O Efcli-MJ pi-Hirtr - IfujOi Q joio m 53 w ce co ni W Fi- Sb (S tj W 3 40 Sft S sf ft> w l 1 X 0 If < 5 K E7 4C le...

Creative VLAN Hopping Attacks

This section is a catchall for various methods to achieve VLAN hopping when trunking is turned off on th port to which the attacker is connected. As these methods are discovered, they tend to be closed by the vendors affected. One tricky attack will take some time to stop on all devices. You might wish to refer t( the previous section on 802.1q if you need more information. The attack works by sending frames with two 802.1q tags instead of one. The attack requires the use of two switches, and...

Other Hardening Options

In addition to the configuration discussed in this section, Chapter 6 contains a fair amount of informatio router and switch hardening, including Routing protocol authentication Denial of service (DoS) mitigation (against and through the router) After hardening a router, it is a good idea to scan it with your favorite port scanner. This ensures th you aren't running any services you thought you turned off. For instance, when testing in my lab fo this book, I realized I accidentally left the...

Table 315 Rogue Devices

Any legitimate networking device popular choices include WLAN AP, DHCP server, router, host Offer services to a user community stealing data as their requests are passed through to the legitimate network Disclosure and corruption of information Until now in the discussion, the spoofing attack class has exclusively contained software-based attacks in which attackers attempt to convince network resources or clients that they are something they are not. In the rogue device attack, however,...

Rogue Device Detection

No matter how well you harden the devices you know about, an intruder can introduce into your network a device of which you are unaware. These rogue devices pose a nasty security problem, particularly in larger organizations. In large organizations, it can be nearly impossible to discover that someone has inserted into the network a device designed to steal passwords, as discussed in the Rogue Devices section of Chapter 3, Secure Networking Threats. On a small network with only five hosts,...

VLAN Trunking Protocol VTP

Oftentimes, it can be a burden to manage a large L2 network with lots of VLANs spread around different switches. To ease this burden, Cisco developed VTP. VTP allows an administrator to configure a VLAN in one location and have its properties automatically propagated to other switches inside the VTP domain. VTP uses a destination MAC address of 0100.0ccc.cccc and a SNAP protocol type of 0x2003. VTP uses th notion of a client and a server to determine which devices have rights to propagate VLAN...

Figure 1026 Semitrusted IPsec Topology Integrated Firewa

Network Topologies With Ipsec

I Psec GakNMy i ic riiiefl Siateiul Firev a ACLfl Slop AN N(HV PMC TrsJiic lo Ci tewey i Psec GakNMy i ic riiiefl Siateiul Firev a ACLfl Slop AN N(HV PMC TrsJiic lo Ci tewey Figure 10-24 shows the main difference in the semitrusted topology when compared to trusted traffic i firewall after decryption. This allows you to define the applications that can be run by remote IPsec conr way that you can restrict the access for Internet users into your private network. Figure 10-24 shows the main...

DHCP Considerations

Dynamic Host Configuration Protocol (DHCP) allows hosts to request IP addresses from a central server Additional parameters are usually passed as well, including DNS server IP address and the default gateway. Attackers could continue to request IP addresses from a DHCP server by changing their source MA addresses in much the same way as is done in a CAM table flooding attack. A tool to execute such attack is available here http packetstormsecurity.org DoS DHCP Gobbler.tar.gz. If successful, t...

ICMP Filtering Recommendations

As you can see, there was a reason that ICMP was created beyond as a playground for attackers. Although most of the 15 ICMP message types can be blocked, several are necessary to the healthy operation of a network. We can rebuild the previous ACLs to allow all the messages we discussed, to block fragments, and to deny any other ICMP messages. Those ACLs are as follows. Router police Serial0 ACL, inbound deny non-initial ICMP Fragments access-list 101 deny icmp any any fragments permit...

Figure 167 Outof Band Management with PVLANs and Firewall

The main benefits of an OOB management design are as follows Production traffic is not impacted by management traffic (and vice versa). An attacker on the production network, or accessing the production network, has no ability to access the management network without first compromising a device that is managed OOB, and even then, the only directly reachable IP on the OOB network is the firewall interface. Because of this lack of attacker access, insecure management protocols can be used on the...

Psec Outsourcing

If ever there were a technology to consider outsourcing, it is IPsec. After you read this chapter, you should strongly consider whether it would be better to just write a nice check to your ISP for an outsourced VPN solution. IPsec deployment is at least 50 percent networking, and good SPs do networking pretty darn well. There are two main outsourcing options Network-based managed IPsec IPsec starts and ends in your SP's cloud. Customer premise equipment (CPE) managed IPsec IPsec starts on your...

Cisco Specific Protocols

Over the years, Cisco Systems has developed a number of proprietary protocols that have been used to perform different functions on an L2 network. Most of these protocols use an IEEE 802.3 frame format with an 802.2 SNAP encapsulation. Most have a Logical Link Control (LLC) of 0xAAAA03 (indicating SNA and the Cisco Organizational Unit Identifier (OUI) 0x00000c. The majority use a multicast destination M address to communicate. This is generally a variation on 0100.0ccc.cccc. The SNAP protocol...

Setting Up Usernames

If you don't have access to TACACS+ or RADIUS, local usernames can be configured on a system as fol Router(config) username username password password Router(config) line vty 0 4 Router(config-line) login local The preceding commands set up a local username and password and then configure the vty lines to use database. To configure TACACS+ access to a system, you must first enable the AAA system You then must define the TACACS+ host and password Router(config) tacacs-server host ipaddr...

Figure 154 Hardware VPN Device Authentication

Carrier Grade Natting

1.1 would Ifte Lo use ihe VPN, Whg( are yogf ciedemjais1 1.1 would Ifte Lo use ihe VPN, Whg( are yogf ciedemjais1 This authentication event generally consists of opening a web page on the gateway and often involves the central site as well to prevent the edge devices from needing to maintain user credential information. The authentication event should be protected by SSL or some other secure mechanism and ideally should use OTP. This authentication provides some assurance that the individual...

Modern Three Interface Firewall Design

Firewall Design

Most designs today use the topology shown in Figure 7-6. This design has become the current gold standard in firewall edge deployments. More-secure options exist (see the next design), but this is the best balance of security, cost, and management. Figure 7-6. Three-Interface Firewall Design Figure 7-6. Three-Interface Firewall Design The biggest benefit this design provides is requiring that all traffic flow through the firewall. This includes traffic from the Internet to the public servers,...

Network Security Promotes Good Network Design

Although it happens far less often now, I still occasionally sit down with a customer who says, OK, the network design is done, now we need to think about security. We're certain we need a firewall and have also heard something about IDS. Designing secure networks in this manner puts you on a fast track to a network design in which the security is tacked on, interferes with the performance of the network, and is viewed by the rest of the Information Technology (IT) staff as a necessary evil and...

TCP Spoofing

Table 3-13 shows the summary information for the TCP spoofing attack. Any attack able to access the raw packet driver in a system Inject unauthorized data into an application that uses TCP as its means of transport Corruption and disclosure of information The TCP header is 20 bytes long (excluding options) and is shown in Figure 3-8. At first glance, it is easy to see why TCP is regarded as the protocol that is more difficult to spoof. It is by far a more complicated protocol than UDP. The...

Table 43 Radius and TACACS

RADIUS and TACACS+ are protocols that offer centralized authentication services for a network. Both operate on the premise that a centralized server contains a database of usernames, passwords, and access rights. When a user authenticates to a device that uses RADIUS or TACACS+, the device sends the login information to the central server, and a response from the server determines whether the user is granted access. RADIUS and TACACS+ servers are commonly called AAA servers because they perform...

Figure 623 CAR

Like the previous network flooding mitigation techniques, CAR must be implemented by your service provider. Since CAR impacts the performance of a router, expect to pay extra to have your ISP run CAR at all times, or you can work out an agreement in which CAR is turned on after you first detect the attack. To configure CAR to implement the three preceding examples, you start by defining the traffic types by ACLs, as shown in the following example. permit means the traffic should be rate limited...

Classic Dual Router DMZ

Double Segment Dmz

As security started to become a problem on the Internet, savvy network administrators migrated to a dual-router system, as shown in Figure 7-4. This is traditionally referred to as a DMZ. Today, many refer to a third segment on a firewall as a DMZ, but this is not strictly correct because the firewall is still protecting the third segment. The main benefit of this design over a single router is that the public servers are separated from the rest of the internal network. A compromise of a server...

Viruses Worms and Trojan Horses

Table 3-26 shows the summary information for virus, worm, and Trojan horse attacks. Table 3-26. Viruses, Worms, and Trojan Horses Table 3-26. Viruses, Worms, and Trojan Horses SQL Slammer (worm) Code Red (worm) Melissa (virus) Application security and antivirus software There used to be a clear distinction between a virus, a worm, and a Trojan horse. A virus is generally thought to be a piece of malicious code that modifies another piece of software on a system. Generally, this requires some...

Classified Network

The classified network has stringent expectations placed on it. To recap, all data must be cryptographically protected on the network, and data must reside in one central location rather than being distributed. Doing this properly in a traditional PC-and-server topology is very problematic based on today's technology. Also, the application requirements of the network are limited, making the flexibility of the PC platform not strictly necessary. As a result, diskless terminals are used with all...

Be Aware of Electromagnetic Radiation

In 1985, the concerns of the paranoid among the security community were confirmed. Wim van Eck released a paper confirming that a well-resourced attacker can read the output of a cathode-ray tube (CRT) computer monitor by measuring the electromagnetic radiation (EMR) produced by the device. This isn't particularly easy to do, but it is by no means impossible. Wim's paper can be found here This form of attack is now commonly called van Eck phreaking. Additionally, in 2002, Markus Kuhn at the...

Content Filtering Summary

Table 4-20 shows the summary scores for the content-filtering options. Table 4-20. Content-Filtering Summary Table 4-20. Content-Filtering Summary Because the ratings in this chapter are skewed toward threat prevention, the overall ratings for the content filtering technologies are lower than other sections. E-mail filtering has a clear security benefit, as do portions of web filtering (mobile code). Proxy servers perform more as a user control function than they do in a security role, so the...

Table 39 Web Application

Cross-site scripting Insecure CGI applications Increased access and disclosure of information Web application attacks are quite varied. Cross-site scripting and insecure CGIs are just two examples. In cross-site scripting, malicious information is embedded into a URL that the victim then clicks. This is an attack that could affect your internal users if they click on a malicious link somewhere on the Internet. Hostile code can be embedded in links on web pages, which can cause the user to...