RE: Application and System Security (was: RE: Honeypot stats)



In article <yndvf.1250$ND4.545@xxxxxxxxxxxxxxxx>, hoff@xxxxxxxxx (Hoff Hoffman) writes:

> Application code that prompts for and verifies and/or that stores
> passwords, or that controls the execution of code, is a risk and is
> an obvious target. When your code is within the TCB, your code is
> a target.

When a participant here gets involved in a meeting discussing plans
to implement application level authentication just go down the list
of authentication safeguards in VMS and ask how the proposed code
will implement each. My absolute favorite is what happens when too
many password changes are made -- it is a familiar shortcoming in
most designs, including a few operating systems. Even the respected
NIST 800-53 document still erroneously says "use a minimum password
lifetime".
.



Relevant Pages

  • Re: What is Forth best at?
    ... Even so, you may reduce the risk, but you might not be ... on the remote target. ... But using a full blown development system on the target is not ... system not to do something incredibly stupid, ...
    (comp.lang.forth)
  • RE: C# Exceptions
    ... no one has successfully executed code using a buffer ... successfully used a .net overrun to execute code. ... do code execution via the stack would be if the target app used. ...
    (Pen-Test)
  • Re: %errorlevel% and run/exec command
    ... Having to code around error levels is like shooting paint balls against a moving target.. ... It is the 'modern' computer 'pulling' methodology, ... but I'm not retrieving %errorlevel% value. ... execution really have dependencies but you can get the output of the ...
    (microsoft.public.scripting.wsh)
  • Re: xpc target ERROR: CPU OVERLOADED AT TIME
    ... To minimize tcp ip network latency between target and host computers, ... With sampling frequencies below 10 kHz, the execution runs normally. ...
    (comp.soft-sys.matlab)
  • Re: What is Forth best at?
    ... be as remote as an spacecraft or I couldn't have installed ... on the remote target. ... It's very useful when you can query the target system. ... against the extra risk of using the target as a development platform. ...
    (comp.lang.forth)