Author Topic: Shape Shifter Botwall  (Read 1218 times)

0 Members and 2 Guests are viewing this topic.

Offline r00k

  • Serf
  • *
  • Posts: 30
  • Cookies: 3
  • rescue my Grub plz
    • View Profile
Shape Shifter Botwall
« on: January 22, 2014, 05:56:49 am »
Shape Security was founded in 2012. They received quite a bit of money from venture funding and Eric Schmidt, around 26 million at the moment. There weren't many rumors about products to be released by the company, until now. They recently announced the Shape Shifter to protect websites from bots by scrambling code so a bot won't see the same code more than once. I don't know much about bots and botnets, but this seems to be getting a lot of funding for what they are doing.

http://www.shapesecurity.com/

Edit: sorry if i placed this in an incorrect topic section.
« Last Edit: January 22, 2014, 06:00:04 am by r00k »
It has become appallingly obvious that our technology has exceeded our humanity.
                                              - Albert Einstein

Offline Darkvision

  • EZ's Fluffer
  • VIP
  • Royal Highness
  • *
  • Posts: 755
  • Cookies: 149
  • Its not a bug, It's a Chilopodas.
    • View Profile
Re: Shape Shifter Botwall
« Reply #1 on: January 22, 2014, 05:31:07 pm »
It is an interesting approach, but i do wonder at its ability to be effective. From what they say in the press release/video it would seem to me that it would be possible to still figure out what each piece is doing through multiple attacks. Even if each ID changes randomly its position/what it is calling to is not. So you would need to program your bot to "find" what that ID is interacting with against a known type. in other words to me this falls under "obfuscation" while nice, once it is figured out exactly how it is done would seem to be rather easy to reverse, at least with the limited information released on it. Basically i would think of this as a "start" but not a finished product yet.


then again i could be completely off, programming is not my strong suit. Still as with any security product i wouldnt trust it without getting to know every thing about it.
The internet: where men are men, women are men, and children are FBI agents.

Ahh, EvilZone.  Where networking certification meets avian fecal matter & all is explained, for better or worse.

<Phage> I used an entrence I never use

Moiz

  • Guest
Re: Shape Shifter Botwall
« Reply #2 on: January 22, 2014, 05:45:59 pm »
No need to say anything


just read the post


http://blog.securitee.org/?p=309

Offline r00k

  • Serf
  • *
  • Posts: 30
  • Cookies: 3
  • rescue my Grub plz
    • View Profile
Re: Shape Shifter Botwall
« Reply #3 on: January 23, 2014, 03:38:55 am »
No need to say anything


just read the post


http://blog.securitee.org/?p=309

Nice read, kinda crazy how they grabbed the developer of PhantomJS  :o .
It has become appallingly obvious that our technology has exceeded our humanity.
                                              - Albert Einstein

Offline ande

  • Owner
  • Titan
  • *
  • Posts: 2664
  • Cookies: 256
    • View Profile
Re: Shape Shifter Botwall
« Reply #4 on: January 23, 2014, 09:11:07 pm »
This is bullcrap all day long. Like the blog above said, 1000 ways around it.


No offence to OP, just to the people making the so-called new security.
« Last Edit: January 23, 2014, 09:11:36 pm by ande »
if($statement) { unless(!$statement) { // Very sure } }
https://evilzone.org/?hack=true

Offline r00k

  • Serf
  • *
  • Posts: 30
  • Cookies: 3
  • rescue my Grub plz
    • View Profile
Re: Shape Shifter Botwall
« Reply #5 on: January 23, 2014, 10:38:43 pm »
This is bullcrap all day long. Like the blog above said, 1000 ways around it.


No offence to OP, just to the people making the so-called new security.

None taken, I suspected that either it wouldn't last long or it had no value in the beginning. The reason i posted it was mainly due to how much funding they received in the past year and from who. Just caught my eye  :)
It has become appallingly obvious that our technology has exceeded our humanity.
                                              - Albert Einstein

Offline Darkvision

  • EZ's Fluffer
  • VIP
  • Royal Highness
  • *
  • Posts: 755
  • Cookies: 149
  • Its not a bug, It's a Chilopodas.
    • View Profile
Re: Shape Shifter Botwall
« Reply #6 on: January 25, 2014, 04:57:13 am »
This is bullcrap all day long. Like the blog above said, 1000 ways around it.


No offence to OP, just to the people making the so-called new security.


well the obfuscation cant hurt, like i said, but its certainly not a complete product. without them releasing more details its an unknown, certainly what is known at this point is not "secure".  however the little they have released is in some ways new(or old applied to a new setting, depending on your viewpoint), if they have more layers, especially truely new and innovative layers it could be a viable piece of tech to buy. The REAL issue wont happen till more is known though, which would be the ability of the technology to mutate with the changes in how automated attacks will change in response to it. In other words if what it ships with can be consistently patched/upgraded to face new threats, or if its something that will simply be bypassed with a few extra bits of code/few extra steps.
The internet: where men are men, women are men, and children are FBI agents.

Ahh, EvilZone.  Where networking certification meets avian fecal matter & all is explained, for better or worse.

<Phage> I used an entrence I never use

Offline ande

  • Owner
  • Titan
  • *
  • Posts: 2664
  • Cookies: 256
    • View Profile
Re: Shape Shifter Botwall
« Reply #7 on: January 25, 2014, 07:17:07 pm »
Security through obfuscation/confusion is a security 101 no-go.
if($statement) { unless(!$statement) { // Very sure } }
https://evilzone.org/?hack=true