Ethical Hacker Community Forums

Ethical Hacking Discussions and Related Certifications => Network Pen Testing => Topic started by: KrisTeason on May 04, 2008, 12:05:50 AM



Title: Countermeasures to Client Side Attacks
Post by: KrisTeason on May 04, 2008, 12:05:50 AM
Hello,

I was doing a research paper on client-side attacks and needed to include a few more counter measures. I know there's alot of security people that use this forum. Anyone willing to throw out some useful countermeasures my way. Thanks in advance!


Title: Re: Countermeasures to Client Side Attacks
Post by: ChrisG on May 04, 2008, 09:46:30 AM
care to put what you have already?

but i'll give you one for free. noscript in firefox.



Title: Re: Countermeasures to Client Side Attacks
Post by: KrisTeason on May 04, 2008, 11:28:56 AM
Yeah, I had a few.
- Keep AntiVirus/Firewall/IDS Software up-to-date
- Keep your OS up-to-date
- Keep your software versions up-to-date
- Refrain from opening mail from untrusted/unknown sources


Title: Re: Countermeasures to Client Side Attacks
Post by: ChrisG on May 04, 2008, 01:43:44 PM
you'll also want to mention a locked down group policy forcing least privilege across the domain.

in there you can do things like setting browser zone and office macro settings to the appropriate level for the organization and ideally not let the user lower those settings.


Title: Re: Countermeasures to Client Side Attacks
Post by: KrisTeason on May 05, 2008, 12:50:03 AM
Ight, thanks for the reply Chris, good to get info from a respected member of this forum.


Title: Re: Countermeasures to Client Side Attacks
Post by: shawal on May 05, 2008, 08:32:58 AM
awarness, one of the most important vectors of the client side attacks is social engineering, training users, and admins and briefing them on these kind of attacks is one counter measure also :)


Title: Re: Countermeasures to Client Side Attacks
Post by: ChrisG on May 05, 2008, 08:14:59 PM
Ight, thanks for the reply Chris, good to get info from a respected member of this forum.

oh well hopefully one of those guys will reply soon.


Title: Re: Countermeasures to Client Side Attacks
Post by: rok on May 06, 2008, 01:10:31 AM
oh well hopefully one of those guys will reply soon.


lol... ;D


Title: Re: Countermeasures to Client Side Attacks
Post by: Bogwitch on May 06, 2008, 04:23:29 PM
It is worth remembering in order to minimise the impact of a client side attack, it is advised to run with least privilege. I have lost count of the number of times I have seen admins surfing the Internet, reading email etc. with full domain admin access...