Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: RebelTex; snopercod; Gigantor; jerri; Texan4W

Okay... Thanks for the links. (Yeah, I need to do my homework... but it's bugging me that I have to become a %^&*$! networking expert. oh well...).

But, I have a couple of questions...

Why would grc.com be concerned about security on a bunch of trivial web-page graphics files? I can access their site otherwise, and get all the printed info; it's just the icons that I can't see... What earthly reason is there to clamp security of some sort on *those*?

Also, when I access their site (or "rfny", or whoever) *directly*, as opposed to through FR, there's no referrer. So what could they be looking for then, that they're not finding? (yeah, it's probably in the documents... I'll look.) (and I'll get a packet sniffer).

What I really want is to figure out a way to feed all these sites a big pile of garbage, when they try to ID me - just because I have a bad attitude.


174 posted on 01/28/2005 12:38:46 AM PST by fire_eye (Socialism is the opiate of academia.)
[ Post Reply | Private Reply | To 169 | View Replies ]


To: fire_eye
"Why would grc.com be concerned about security on a bunch of trivial web-page graphics files? I can access their site otherwise, and get all the printed info; it's just the icons that I can't see... What earthly reason is there to clamp security of some sort on *those*?"

All websites should be secure to prevent hacking and DOS attacks.  How do you think hackers have managed to  replace images that a web page has inserted with photo-shopped images on well known websites.   The hacked images were not in a secure directory or the site had other holes.    If I take the time to create, locate, or buy images, then I sure don't want them messed with, photo-shopped, or replaced with something embarrassing or something that would harm my image and reputation.  That's why.  I hope you don't have any kind of business website - if you do, you're asking for trouble without proper security.  (Web hosts usually provide some security for their clients, but it varies by provider.)

"Also, when I access their site (or "rfny", or whoever) *directly*, as opposed to through FR, there's no referrer. So what could they be looking for then, that they're not finding? (yeah, it's probably in the documents... I'll look.) (and I'll get a packet sniffer)."

What they are not finding is the reference to the web page that calls up the pictures, since you were not on that page.  As I explained before, the secure server looking for the reference to the web page is not going to serve up the images if the reference is missing or invalid.   Browsers normally have this 'referrer' info in the headers sent to the server.  Browsers also keep a history of visited websites in a directory on your hard drive (you can turn this off).  BTW, the reference info is the info about the web page or web pages server or domain  - NOT YOUR COMPUTER OR YOUR INFO.   If someone were capturing and inspecting this info, what they would see is what the last web page that a computer with the IP address of xxx-xxx-xxx-xxx  visited.  And the IP address is probably a proxy that your ISP uses.  (I hope you don't use a fixed IP address - read grc.com for info about why that's not a good idea.)

Same thing happens when you are on that page and you have the "information about visited web sites" turned off (blocked - a setting in your firewall, browser, anti-spyware, or pop-up blocker)  This is ONLY 1 of the many settings for these security software programs, and you can turn it on/off (permit/block).

"What I really want is to figure out a way to feed all these sites a big pile of garbage, when they try to ID me - just because I have a bad attitude."

Again, they are not trying to ID you - just verify that you are visiting an authorized site so they don't get hacked or have unauthorized access to sensitive data.  (I guess they could use SSL and require registration with a user name and password, but that would be a real hassle just to see some images and prevent hacking - really cuts down on the number of hits to a web page. /sarcasm)

Don't worry about these type of sites (the 2 under discussion) - they could care less about you and your personal info.   The one's that are a nuisance are the one's that have tons of ads and pop-ups, all of which are handled well by good  anti-spyware & pop-up blocker programs.   Feeding them 'a big pile of garbage' is a waste of time and could bring DOS (Denial of Service) criminal and civil charges against you - don't go there.  (Hackers, OTOH, are fair game, IMHO).

You might want to take some courses on networking, network security, HTML, browsers, and building secure websites.  This would enhance your understanding.

175 posted on 01/28/2005 11:46:27 PM PST by RebelTex (Freedom is everyone's right - and everyone's responsibility!)
[ Post Reply | Private Reply | To 174 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson