|
|||||||||||
|
RES: Honeytokens and detection
From: Augusto Paes de Barros <augusto(at)paesdebarros.com.br>
Date: Tue Apr 08 2003 - 02:49:24 EDT
You are right. Public known honeytokens wouldn't be of much use. Each company should create its own fake data, to add a random factor and increase the chance of being usable on these cases. Honeytokens as database rows raises some additional issues that should be remembered. All apps that do things like "SELECT * FROM TRANSACTIONS" can make the alarm sound. Regards, Augusto.
-----Mensagem original-----
Just my two cents.
David Zbonski
--
ALERT: Exploiting Web Applications- A Step-by-Step Attack Analysis Learn why 70% of today's successful hacks involve Web Application attacks such as: SQL Injection, XSS, Cookie Manipulation and Parameter Manipulation. http://www.spidynamics.com/mktg/webappsecurity71 Received on Fri Apr 11 18:03:33 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:11 EDT |
||||||||||
|
|||||||||||