Great Circle Associates Firewalls
(September 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: commerical Internet gateway products
From: tadusa!jim @ uunet . UU . NET (Jim Thompson)
Date: Thu, 24 Sep 92 17:37:30 CDT
To: sidney @ borland . com
Cc: firewalls @ GreatCircle . COM

> Can anyone poke any holes in the method or come
> up with advantages to using a gateway?

Yea, what happens when someone within your organization erects a
service that listens on a non-privliged port, (or SMTP/NNTP), and
execs a shell, e.g. an 'inside' job.  Don't say it can't happen.  

Worse, some remote interloper contacts an X server (port 6000, well
outside the priv-ed range) with*IN* Borland, and starts grabbing bits
off the 'screen'?

The idea behind what Xerox, Sun, and other companies do is to completely 
shut off access by not passing *any* packets.  The proxy services are just
a way to restore part of what is lost by doing this.

Jim


Indexed By Date Previous: Re: Suffering from Postscript Envy? Read this!
From: mis @ seiden . com (Mark Seiden)
Next: High speed firewalls??
From: cary @ scripps . edu (Steve Cary)
Indexed By Thread Previous: Re: commerical Internet gateway products
From: sidney @ borland . com (Sidney Markowitz)
Next: Re: commerical Internet gateway products
From: John Larson <jlarson @ parc . xerox . com>

Google
 
Search Internet Search www.greatcircle.com