Ethical Hacking Techniques to Audit and Secure Webenabled ..., email with the link in a web enabled email client. Example 4 shows JavaScript embedded. as the value of one of the parameters of the login page. ...,
Why Firewalls Fail to Protect Web Sites
Short summary:
The reason the firewalls did nothing to prevent the hacks is because the firewall is ... The failure of a firewall to protect the web server is nothing new. ...
Long summary:Why Firewalls Fail to Protect Web SitesPage 1 Copyright 2002 Lockstep Systems Inc.1Why Firewalls Fail to Protect Web SitesA White Paper byKarl ForsterLockstep Systems Inc.+148059694321877WEBFIXRinfo@lockstep.c omwww.lockstep.comPage 2 Copyright 2002 Lockstep Systems Inc.2Why Firewalls Fail To Protect Web SitesThe purpose of this document is to outline how a firewall works and how hackers get through your firewall and alter the web site content on your web server.The Purpose of a FirewallThe firewall was designed as a gateway to allow or deny access to network resources. The firewall makes its decisions based on what the user wants to connect to not what their intent is. When you have a web server the firewall must grant access to the web site to allow people on the Internet to be able to give Internet visitors access to the web site content. Therefore when a hacker requests to access the web server the firewall has essentially been designed to grant access to the hacker.A Brief History of FirewallsThe firewall was invented about a decade prior to the invention of the web server and the original goal of a firewall was to prevent users on the Internet from accessing selectivenetwork resources. Initial firewalls were designed as simple packet filters they simply looked at what the user wanted to connect to and compared that to a list of allowed and disallowed resources. If the user requested a connection to an allowed resource the firewall allowed access to the user. If the user requested a connection to a disallowed resource the firewall did not allow the user access.When the firewall is installed the administrator gives the firewall a list of the resources they want to allow access to and a list of resources to which access should be denied. Typically the administrator allows access to resources such as email servers and web servers. Each resource available on a network is assigned a port number the number that corresponds to the type of resource. When the u ...
Source: www.lockstep.com