2 ms·
> Attackers usually don't know the country of the user Nothing a little recon or social engineering can't solve. > it's not as easy as it sounds to find a VPN
by jsploit 7y ago
> Attackers usually don't know the country of the user
Nothing a little recon or social engineering can't solve.
> it's not as easy as it sounds to find a VPN or an open proxy in any country
Only for some small/niche countries perhaps. Worst case, an attacker can rent a VPS in the target country.
Perhaps a city-based lock would be more effective.
- user5994461 7y agoMost attacks are opportunistic, trying credentials that were leaked online or brute forcing simple passwords. It's also heavily weighted from russia, china, tor, open proxy, non-reputable hosting and cheap VPS. Each of these can be detected and blocked. Attacker do not maintain proxies, especially not proxies across tens of developers countries, and if they that would be organized crime and it's a whole new level. By the way, banking trojans evolved to operate from the browser of the victim specifically to evade these protections. Should I cover all these in a blog post if it's something you're interested in?
- jsploit 7y agoI think you're deviating from the topic of protecting against the vulnerability HackerOne encountered: using a leaked session cookie. In their case, let's say the victim analyst was based in the United States, and they have implemented your proposed session country-lock. I also happen to reside in the US, so the country-lock protection is worthless. For other cases, you can _try_ to block proxies, VPNs, TOR, VPSs... but that in itself is perhaps a usability fail.