COSC 4P14
What could possibligh go wrong?
Brock University
Brock University What could possibligh go wrong? 1 / 32
COSC 4P14 What could possibligh go wrong? Brock University Brock - - PowerPoint PPT Presentation
COSC 4P14 What could possibligh go wrong? Brock University Brock University What could possibligh go wrong? 1 / 32 Common attacks and exploits Weve talked about how to use individual tools (encryption, authentication, etc.), but theres
Brock University What could possibligh go wrong? 1 / 32
Brock University What could possibligh go wrong? 2 / 32
Brock University What could possibligh go wrong? 3 / 32
◮ Why not?
Brock University What could possibligh go wrong? 4 / 32
Brock University What could possibligh go wrong? 5 / 32
◮ Check out chrome://net-internals#hsts
Brock University What could possibligh go wrong? 6 / 32
Brock University What could possibligh go wrong? 7 / 32
Brock University What could possibligh go wrong? 8 / 32
Brock University What could possibligh go wrong? 9 / 32
◮ Will people connect? Maybe, maybe not.
◮ Chances are, you’ll get a few more biting Brock University What could possibligh go wrong? 10 / 32
Brock University What could possibligh go wrong? 11 / 32
◮ No, seriously, don’t ◮ https://m.xkcd.com/792/ ◮ https://m.xkcd.com/1286/
◮ https://m.xkcd.com/936/
Brock University What could possibligh go wrong? 12 / 32
Brock University What could possibligh go wrong? 13 / 32
Brock University What could possibligh go wrong? 14 / 32
◮ Chances are, someone’s fallen for it!
Brock University What could possibligh go wrong? 15 / 32
◮ Oh hey, what was that about two-factor authentication earlier...?
Brock University What could possibligh go wrong? 16 / 32
Brock University What could possibligh go wrong? 17 / 32
Brock University What could possibligh go wrong? 18 / 32
Brock University What could possibligh go wrong? 19 / 32
◮ From cheap computing resources on a farm, or ◮ Performed without the hosts’ owners’ knowledge, because their
◮ A classic ping attack simply organizes enough pings to flood the target ◮ A ping of death uses a massive IP packet, which can also trigger
◮ A smurf attack is a sneaky bit of ventriloquism: send out a broadcast
Brock University What could possibligh go wrong? 20 / 32
Brock University What could possibligh go wrong? 21 / 32
Brock University What could possibligh go wrong? 22 / 32
◮ https://xkcd.com/1354/
Brock University What could possibligh go wrong? 23 / 32
◮ Sanitization of inputs is really important ◮ To some extent, good design can mitigate this ⋆ e.g. one server can make requests of another (even deeper) server,
◮ And obviously, one way or another, replays shouldn’t be viable Brock University What could possibligh go wrong? 24 / 32
Brock University What could possibligh go wrong? 25 / 32
◮ Everything from SQL injection, to MitM ◮ Basically, all of the fun script-kiddie stuff
Brock University What could possibligh go wrong? 26 / 32
Brock University What could possibligh go wrong? 27 / 32
Brock University What could possibligh go wrong? 28 / 32
Brock University What could possibligh go wrong? 29 / 32
Brock University What could possibligh go wrong? 30 / 32
Brock University What could possibligh go wrong? 31 / 32
Brock University What could possibligh go wrong? 32 / 32