Friday, May 31, 2002

Yahoo Chief Scientist Describes Web Attacks
Manber presented his talk, "Exploits of Large-Scale Web Services and Counter-measures," at the 2002 IEEE Symposium on Security and Privacy, in Oakland (go to www.ieee-security.org/TC/SP02/sp02prelimprogram.html for more information).

The kinds of attacks that caused Yahoo the most problems weren't traditional OS or Web server attacks, but service abuses, according to a report on the Dr. Dobb's Journal Web site (at www.ddj.com/news/fullstory.cgi?id=5887).

Yahoo's top Web service security problem is abuse of services by automated software agents. HTML screen-scrapers were a big problem in Yahoo's financial section, as some were screen-scraping HTML pages to retrieve real-time stock quotes and then reselling the information.
http://www.eweek.com/article/0,3658,s=709&a=27324,00.asp

No comments:

Post a Comment

con·cept