Slashdot Mirror


Security Flaws In Aussie Net Filter Exposed

Faldo writes "There's a three-part interview with a computer security expert on BanThisURL that goes into the flaws in the Aussie net filtering scheme. In addition to SSH tunnels and proxies, more worrying problems like trojaning the boxes to set up man in the middle attacks (which the interviewee has done in his lab), cross site scripting and the Australian blacklist leaking are all discussed. Worrying and relevant, especially since Thailand's blacklist has just been leaked."

13 of 182 comments (clear)

  1. From the article by thewils · · Score: 4, Funny

    I've played with a lot of these boxes and the chances of having no security vulnerabilities at all is extremely low. In our testing we haven't actually found a box that we've been happy with the security of, except for little dedicated and extremely cut down boxes, but nothing of this type.

    Disagree, they could just use a Windows box for this, as long as they keep it up-to-date with patches they'll be fine, right?

    --
    Once I was a four stone apology. Now I am two separate gorillas.
  2. Re:But What About The Children/Terrorists/Etc. by dgatwood · · Score: 4, Funny

    Politics tends to attract those who want power, and those who want power are seldom in the best interests of those who are being led. Therefore, an ideal political structure would include a benevolent dictator randomly chosen from the population, who would be deposed if another group of a dozen randomly chosen people decide to throw him/her out. It would then have a mock electoral process to elect fake leaders. The resulting political body's sole purpose for existence would be bringing politicians out of the woodwork and keeping them isolated from polite society.

    I hereby nominate CmdrTaco as the first benevolent dictator. All in favor, say aye!

    --

    Check out my sci-fi/humor trilogy at PatriotsBooks.

  3. Re:Not really news? by D+Ninja · · Score: 5, Funny

    There are flaws in everything.

    Obviously you haven't yet heard of Natalie Portman.

    Otherwise, yeah, you're right.

  4. Re:Not really news? by maxume · · Score: 5, Funny

    You are entirely happy with her decision not to sleep with you?

    --
    Nerd rage is the funniest rage.
  5. Re:why would the list have to "leak"? by Qzukk · · Score: 4, Funny

    doesn't the govenment publish the blacklist?

    I searched for it online but every time I tried to view the list, I got a page that said the site had been blocked.

    --
    If I have been able to see further than others, it is because I bought a pair of binoculars.
  6. Re:It is completely ignorant to think... by Anonymous Coward · · Score: 5, Funny

    Also, only one suffered from a Celine Dion soundtrack.

  7. Re:It is completely ignorant to think... by ultranova · · Score: 2, Funny

    There already is a word: Hubris

    The grandparent is too good to use borrowed words like "hubris". His supremacy deserves better.

    --

    Forget magic. Any technology distinguishable from divine power is insufficiently advanced.

  8. Re:It is completely ignorant to think... by Anonymous Coward · · Score: 5, Funny

    We _ALL_ suffered from a Celine Dion soundtrack.

  9. Re:Not really news? by genner · · Score: 3, Funny

    There are flaws in everything.

    Obviously you haven't yet heard of Natalie Portman.

    Otherwise, yeah, you're right.

    She lacks stone skin and grits. How can you overlook such obvious flaws.

  10. Re:It is completely ignorant to think... by Anonymous Coward · · Score: 5, Funny

    But we all benefited from Kate Winslet's bare boobs.

  11. Re:It is completely ignorant to think... by Paradise+Pete · · Score: 5, Funny

    Actually all three sank roughly the same way.

    For sufficiently small values of actually.

  12. Re:But What About The Children/Terrorists/Etc. by BlackCobra43 · · Score: 3, Funny

    To block Bit Torrent, you simply have to try to NOT block Bittorrent..and fail.

    --
    I never spellcheck and I freely admit it. Save your karma for more worthwhile "lol erorrs" replies
  13. Who says filtering is hard? by David+Gerard · · Score: 2, Funny

    "We have buttiduously canvbutted the industry, buttessed what is available and buttembled the finest selection of contractors for this buttignment. The filters will buttociatively clbuttify all communications and filter then, I can butture you, rebuttemble them with surpbutting exacbreastude in any quanbreasty. Consbreastuents can be rebuttured that a mulbreastude of industry compebreastors will butture quality and keep our clbuttrooms safe. EDS Capita Goatse will not embarbutt us."

    The plans have attracted wide criticism. "It will only give supersbreastious rebutturance to medireview thinkers," said EFA. "Automated systems won't solve human problems like loveual harbuttment. Mbuttacring the written word into a Picbutto painting is not the anbreastank missile of Internet safety."

    Unions also butterted that such close buttessment of staff in the workplace would hamper efficiency and could verge on workplace harbuttment. "Watermeloning cranberries."

    The government was unfazed. "Butterting free speech is one thing, but a triparbreaste committee considers that that does not justify mere pbuttive breastillation at the expense of others."

    The first filtering offices will be set up in Arsenal, Penistone and Scunthorpe.

    --
    http://rocknerd.co.uk