. , , ,

,,,

,






:


:

. -220
. .

2002


, , . , , - .

, , , . -, . , , , web-, , " " . -,

, ICQ. , . , - , ( , )

.

, ? , , , , .


, ,- . . " " , . , . Windows 95 98. .


.

Windows 9 - . , , " ". , . , . ,

. , , .

, .

, , , - . - . - , (,

, ). , . , . , , , . - - , ,

,

. , ( ), -. - , : , , .

,

. Microsoft Internet Explorer, Microsoft Outlook Express Outlook Microsoft Office .

, web-. , , ( Windows NT, 2000 , , ). , , .

?

- .

. - , , .

. ,

. ActiveX, HTML- , , (, Media Player). , Microsoft

- . ,

, . -

, , - . , . , Java,

ActiveX, cookie, , .

...

firewall - , .

firewall , . , - , . Firewall ,

(, ). firewall web-: ActiveX, (JavaScript, Visual Basic), Java-.

, ,

firewall
-

.

. , , , , . , (Nimda, Sircam). . . ,

, , , . , . . , , - . Microsoft ( )

(http://windowsupdate.microsoft.com). , (Internet Explorer, COM+), , " " (Service Pack), . RollUp Package, , Service Pack . , ,

, , .

, , , . , , . , . , , . ,

firewall , . . ,

: Russian Security News-line (http://bugtraq.ru/rsn), SECURITY.NNOV (http://www.security.nnov.ru/), CERT Coordination Center (http://www.cert.org).

www.cert.org -

!

. , . , , . , . . , , , , . . , , .

Microsoft ,

, . - - . , , - , Microsoft Microsoft Baseline Security Analyzer. , , , -

, . . , MBSA , . . MBSA 1.0 Finjan Malicious

Code Research Center , XML

. , , , . , , , HTML-. .

?

- . , , . , , , , . , , , . .

, . , IRC ( I-Worm.LoveLetter, ILOVEYOU), Microsoft - Internet Information Server, ( , , Nimda).

( , ). - BadtransII

, LOG- . - Nimda "" . ,

, . , , , .

, WWW - , . , - - , . , , .

, , , www- , .

, - . (. www-). , , , EXE-, MS Office .

- web-. HTML- Javascript, , Java, ActiveX ( MS Windows).

, . , Java- (sandbox), . Javascript , Javascript .

""

, . , .

web- Javascript. , :


Example of DoS



- , . - , (). , - . URL, , - . :

href=http://www.cracker.com/
onMouseover=http://www.goodbank.com/;
return true>
Click here to enter your credit number

, , , www.goodbank.com, , , www.cracker.com. www.cracker.com.

Javascript . - , - . , , Javascript . , .

, - WWW-, Javascript HTML- . cross-site scripting , . , WWW- , . , . , , >Click here

WWW- example.com, , .

Cross-site scripting SSL

cross-site scripting , SSL. , WWW-, , , , .

cross-site scripting .

. , ( ActiveX, Java Javascript) . , . , , , , , . , , , .

Java, ActiveX Javascript, .

, HTTP- . , , WWW- . Digest- ( ) - . .

, , www-, , IP- , URL , ( ), URL , . -, WWW .

, GET, LOG-, URL-. POST , .

, ( , - history). ( ).

www- (, -) cookies (, , ). , ( - , cookies). cookies WWW. cookies, .

- SSL

, -, SSL ( - TLS).

SSL TCP/IP (TCP) . SSL (, , ) . HTTP , , HTTP- .

SSL, HTTP- , SSL ( ). URL , SSL, "https://". HTTP- () SSL-. , "" . , . , VeriSign. , , .

, ( , . .).

SSL -

SSL -. HTTP- , . - HTTP-. CONNECT HTTP-.

CONNECT -, TCP- , . , - CONNECT, , 443, HTTP SSL.

- -

- HTTP- , .

, WWW - . , HTTP-, - . HTTP- , 80, - (80-86, 8000-8006, 8080-8086, 8888).


- ( ):

  • ;
  • ( CONNECT, -);
  • : , ;
  • ;
  • , (, , , - , );
  • , , , (, ).
  • HTTP - - FTP, FTP-.

- , . - IP-, -.

- WWW-, Proxy-Authorization. -, , 407 Proxy Authentication Required Proxy-Authenticate, WWW-Authenticate. Digest Proxy-Authentication-Info.

, www- - HTTP- - , . (Authorization Proxy-Authorization) , .

, , ( ). , Basic Ethernet - , Digest.

, , WWW , . - .

WWW - , HTTP.

HTTP : () . TCP HTTP- - 80. URL - (), , .

, , URL, . . HTML- , " ", . , , , , , Content-Type, I- .

www-. : , . HTML-, .

HTML-. , , . . , .

: action method. URL, , - .

: GET POST. GET , , URL . URL , , : "/cgi-bin/dir/script.pl?name=John&age=25 &hobby=reading&hobby=football". , "=", . POST : "-me=John&age=25&hobby=reading&hob-by=football" , URL .

, HTTP- www-. HTTP- , , HTTP- , , . , , . WWW , HTTP- - front end www-, , , - back end. : , : HTTP- - - .

CGI

CGI. HTTP- , , , . HTTP- , QUERY_STRING, URL, ( , , , GET). , CGI- , . , , , URL HTTP- , . CGI-. , , HTTP- . , CGI-, - Content-Type.

- HTML-. (, ). , HTTP- , . . , , PHR ASP (Active Server Pages), JSP (Java Server Pages). CGI, , , , CGI-, , .

- Javascript. , Javascript, , . , Java. HTML- , , - , Java-. http://java.sun.com.

HTTP- - HTTP-, -. . - : , , , URL cgi cgi-bin, , . , Cache-Control, . : Last-Modified Expires - " ".

, WWW . - , , HTTP-. WWW-Authenticate Authorization. : Basic Digest, . ; MD5.

WWW , , , : , () .

, mirror world, , . . , , DNS-, -. , , , , , HTML- , . , , . , .

WWW. HTTP-. , , HTTP- CGI- ( CGI-). , , - HTTP-. , CGI- , . CGI- .

, .

, , , -, , .

, , .


.
, , . , .., , - . , : , .

, , , , , . - .

. , , . , , , . . , , , () .

, , $1 ., $20 . , . ? , ?


, . , , , .

, , . .

.

, , , . . : (, ).


, , . , : , , , . , . .

. , , . , - , , , 2 . , , , .

, . , .

(), . "" . : (, ). , "" . , , .

. , , . , . , - (). 80 , , .
. . , . -, . -, . -, , , .

, , . . , . . () (VPN).

, () , . , , . VPN , , .

, , , . - . , .

. . - , . , , , .

, Internet/Intranet. , , , ( , , ).

, , , c - (). , , , , , - / ( , ) , ( ), .

, () , . : , : , , .

. (Public Key Infrastructure - PKI). , PKI, , , : ( ) , , , () , . , , . , , ,
, . , PKI , , .

. , , , , . : , , , , . . , , VeriVoice Security Lock VeriVoice , , . , , (, ).

. .

, . , , , . , , , . USB, PS/2 , , .

, , , . , , ; .

, , - , , - . , , (, , ) .

- ( ). , , , . , , , , PKI. - (, LAN, WAN VPN) , - , , . , , ( , "" " "), Internet/Intranet , . Orga Micardo - Standard, Public Dual - EEPROM 4 32 , 32 64 ROM ( ). Orga MICARDO Software Development Kit, .

, . $40, , , ( , , , ), , EEPROM-. $100, - $150.

, . , Smart Credit Card Internet Keyboard Presario 5000 , , (, ).

, , . -, , . , (, ), , , .

-, PCMCIA , , .

eToken

- , . ; , eToken R2 Aladdin 64 , DES-X 120- .

, , , , , , . eToken Microsoft CryptoKey MS Crypto API CSP (Crypto Service Provider) X.509 . - Digital Signature Trust (DST) TrustID, eToken Internet Explorer Netscape. RSA-KEON, PKI, eToken Microsoft Outlook, Outlook Express Netscape Messenger.

, , . , Windows 2000 Windows XP . Aladdin PKINIT Kerberos 5. . eToken , , .

, : USB, , . " " (hot plug), .

: USB, Aladdin.

, , . , , , , CD- , .

Aladdin. : , 30 . , . SDK, , / .

, " " , 64 , . , eToken R2, DESX 120 . , eToken PRO, , RSA/1024, 3DES (TripleDES), SHA-1, MD5 (Private) , .

, . Siemens CardOS/M4 FAT. , Windows.

, , - , 16- , DESX-. , , , . , - , .

eToken R2 , , , PIN-. John the Ripper , PIN- 1 .

. , - . -, .

, , ( , ), . , , . , , , CuteFTP, GetRight, GolZilla, Net Sonic . (spyware).

spyware, Aureate, Cydoor, DoubleQick, EverAd, OnFlow WebSOOO. adware, spyware .
, , , , -. , .
spyware. spyware (, Y3K, Spektor, AgentSpy . .). , . , , .

- , : " " , , . . . . , - .

. , - . . -firewall, . . , . , , , .

?

. , - , . - , , Napster ? , Windows Media Player 8, Windows XP, , . , , , ( , Microsoft) . , , . , - Microsoft , Associated Press.

, . , Investigator . , . Investigator , , , . , web-, .

, Investigator , . . -. . 200 . , ?

:

. Chip 2002
. Chip, 2002
. 兔- " ""
. , . WORLD WILD WEB Chip, 2002
. Ô Chip, 2002

:
Sec.Ru -
- www.pps.ru/bib

: : . -220 . .

 

 

 

! , , , .
. , :