Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2001 > May 2001
Page art

Preparing for the Script-Form Attack

Gilbert Held

Today we live in an electronic era, with the use of the Internet growing by leaps and bounds. Along with this growth, we have unfortunately witnessed an increase in the distribution of viruses, denial-of-service (DoS) attacks, and the break-in and modification of home pages on Web servers operated by government agencies, commercial organizations, and academia. The purpose of this article is to acquaint readers with a relatively new type of network-based attack that can cost your organization money. I will describe what I call a "script-form" attack; I will first examine how this attack can occur, and some prevention methods.

Overview

The Web has changed the way many businesses operate. The Web is a valuable place to obtain information and to shop. In addition to mailing brochures, many organizations highly automate their Web presence. Thus, brochure requests generate lists of mailing labels that require little human intervention. When you consider the cost of postage, it is quite possible that every form filled out by an Internet surfer winds up costing more than five dollars when the cost of the brochure, the envelope, and the postage are included as factors.

While it is often difficult to explain the logic behind network attacks, we know they occur and although I'm hard-pressed to determine why anyone would cause an organization to spend needless funds shipping brochures around the world, it is a vulnerability to consider. Because we live in an era of automation, the repeated completion of a form by a script using a database of names and addresses represents a "script-form" attack and is the focus of this article.

I examined several Web sites offering books, brochures, and other literature. The creation of a script to execute a form was easy to accomplish.




MarketPlace

Build IT Knowledge with Current & Trusted Content
Helps Employees Develop & Hone New Technical Programming Skills. Sign Up & Get Full Access.

Workflow Enabled Help Desk & IT Service Management
Automate service desk activities and integrate processes across IT. Learn more here.

Flowcharts from C/C++ code -- Free trial download
Understand C/C++ code in less time. A new team member ? Inherited legacy code ? Get up to speed faster with Crystal Flow for C/C++. Code-formatting improves readability. Flowcharts are integrated with code browser. Export flowcharts to Visio.

Discover WinDev 11 RAD
and develop 10 times faster ! ALM, IDE, .Net, PDF, 5GL, Database, 64-bit, etc. Free Express version

Wanna see your ad here?