Full Disclosure mailing list archives
Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection
From: Nelson Brito <nbrito () sekure org>
Date: Tue, 1 Jun 2010 10:27:48 -0300
Okay, but why did you mention AV as a client-side protection? It leads to a discussion about client-side protection, anyways. Cheers. Nelson Brito Security Researcher http://fnstenv.blogspot.com/Please, help me to develop the ENG® SQL Fingerprint™ downloading it from Google Code (http://code.google.com/p/mssqlfp/) or from Sourceforge (https://sourceforge.net/projects/mssqlfp/).
Sent on an iPhone wireless device. Please, forgive any potential misspellings!
On Jun 1, 2010, at 9:58 AM, rajendra prasad <rajendra.palnaty () gmail com> wrote:
Hi List, I have started this discussion with respect to Network IPS. Thanks RajendraOn Tue, Jun 1, 2010 at 1:08 PM, rajendra prasad <rajendra.palnaty () gmail com > wrote:Hi List,I am putting my thoughts on this, please share your thoughts, comments.Request length is less than the response length.So, processing small amount of data is better than of processing bulk data. Response may have encrypted data. Buffering all the client-server transactions and validating signatures on them is difficult. Even though buffered, client data may not be in the plain text. Embedding all the client encryption/decryption process on the fly is not possible, even though ips gathered key values of clients.Most of the client protection is done by anti-virus. So, concentrating client attacks at IPS level is not so needed.Thanks Rajendra _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Why the IPS product designers concentrate on server side protection? why they are missing client protection rajendra prasad (Jun 01)
- Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection Nelson Brito (Jun 01)
- Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection Valdis . Kletnieks (Jun 01)
- Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection rajendra prasad (Jun 01)
- Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection Nelson Brito (Jun 01)
- <Possible follow-ups>
- Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection Nelson Brito (Jun 01)
- Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection Nelson Brito (Jun 01)
- Re: Why the IPS product designers concentrate on server side protection? why they are missing client protection rajendra prasad (Jun 02)