<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site hacked and IPS didn't detect a thing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/site-hacked-and-ips-didn-t-detect-a-thing/m-p/899271#M84972</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume the application is custom, not purchased "off the shelf"? It looks like your custom application is vulnerability to some form of URL tampering,  but without more details it's hard to be sure.  IDS is a signature based technology and as such doesn't do such a good job of detecting flaws in custom applications. If you allow HTTPS, it has no chance. There is something called an application firewall that is generally more effective for securing custom applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"isn'this some known form of SQL injection"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;based on what you provided, I would say no. It looks like simple URL tampering.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"is there some good explanation about these types of attacks and what should be done to further prevent this type of attacks"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see [variable manipulation]: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.owasp.org/index.php/OWASP_AppSec_FAQ" target="_blank"&gt;http://www.owasp.org/index.php/OWASP_AppSec_FAQ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fix your application. knowing how to do that is beyond the scope of this forum. hopefully the owasp guide and site can help you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jan 2008 13:51:31 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2008-01-08T13:51:31Z</dc:date>
    <item>
      <title>Site hacked and IPS didn't detect a thing</title>
      <link>https://community.cisco.com/t5/network-security/site-hacked-and-ips-didn-t-detect-a-thing/m-p/899269#M84968</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;one of our websites was hacked, the attacker used weakness in the scripting, what he did was added to the address "&lt;A class="jive-link-custom" href="http://www.xxx.com/details.asp?id=xxx+update+textnews" target="_blank"&gt;http://www.xxx.com/details.asp?id=xxx+update+textnews&lt;/A&gt;+..." and by this he changed the main page.&lt;/P&gt;&lt;P&gt;My question is why the IPS did not detect it ? isn'this some known form of SQL injection ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there some good explanation about these types of attacks and what should be done to further prevent this type of attacks &lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:55:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-hacked-and-ips-didn-t-detect-a-thing/m-p/899269#M84968</guid>
      <dc:creator>josephium</dc:creator>
      <dc:date>2019-03-10T10:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Site hacked and IPS didn't detect a thing</title>
      <link>https://community.cisco.com/t5/network-security/site-hacked-and-ips-didn-t-detect-a-thing/m-p/899270#M84970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NB: xxx is not our website i used it as a fill in the blanks instead of the original website&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 06:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-hacked-and-ips-didn-t-detect-a-thing/m-p/899270#M84970</guid>
      <dc:creator>josephium</dc:creator>
      <dc:date>2008-01-08T06:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Site hacked and IPS didn't detect a thing</title>
      <link>https://community.cisco.com/t5/network-security/site-hacked-and-ips-didn-t-detect-a-thing/m-p/899271#M84972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume the application is custom, not purchased "off the shelf"? It looks like your custom application is vulnerability to some form of URL tampering,  but without more details it's hard to be sure.  IDS is a signature based technology and as such doesn't do such a good job of detecting flaws in custom applications. If you allow HTTPS, it has no chance. There is something called an application firewall that is generally more effective for securing custom applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"isn'this some known form of SQL injection"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;based on what you provided, I would say no. It looks like simple URL tampering.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"is there some good explanation about these types of attacks and what should be done to further prevent this type of attacks"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see [variable manipulation]: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.owasp.org/index.php/OWASP_AppSec_FAQ" target="_blank"&gt;http://www.owasp.org/index.php/OWASP_AppSec_FAQ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fix your application. knowing how to do that is beyond the scope of this forum. hopefully the owasp guide and site can help you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 13:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-hacked-and-ips-didn-t-detect-a-thing/m-p/899271#M84972</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-01-08T13:51:31Z</dc:date>
    </item>
  </channel>
</rss>

