Great Circle Associates Firewalls
(March 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: mis-use of telnet (was: Re: Hey the crackers have a new twist...)
From: ericm @ MicroUnity . com (Eric Murray)
Date: Tue, 29 Mar 94 10:44:35 PST
To: heiser @ world . std . com (Bill Heiser)
Cc: firewalls @ GreatCircle . COM, heiser @ world . std . com
In-reply-to: <199403291340 . AA21938 @ world . std . com>; from "Bill Heiser" at Mar 29, 94 8:40 am

Bill Heiser wrote:
> 
> 
> Eric Murray <ericm @
 MicroUnity .
 com> wrote:
> 
> > Actually, it occurs that in this second scenario -- a confederate of the
> > baddies, perhaps a disaffected employee inside your network -- even
> > authentication of outbound connections wouldn't help you: if this
> > insider is `trusted' -- allowed to make outbound connections through
> > (say) your telnet application gateway -- then she can if so determined
> > misuse this channel anyway (eg:


Bill, I didn't write that.  Watch your attributions please.


Not that I don't agree with it, as far as it goes.

  
> >     connects  out via your telnet application gateway to a port on a <---**
> >     collaborating remote system, which echoes back  commands  to  be
> >     executed  on  your  local system; user's local program -- either
> >     custom written, or `expect' wrapped around  an  ordinary  telnet
> >     client(?)  -- then acts accordingly, and echoes resulting output
> >     back down the line
> 
> 
> ... Well how about if the application gateway does not allow internal
> users to "telnet to a port", but only allows telnet to the standard
> remote telnet port? ...

Still a problem, if they can telnet they can send data.
 
Any halfway determined employee can get company secrets out past
any resonable security.

You have to draw the line somewhere.  At some point you will have to
trust the employees.  If not, you will become more and more parnoid
and restrictive until you wind up locking them in a cage
and poking them with sharp sticks. :-)


--
     ericm         ericm @
 microunity .
 com


Follow-Ups:
References:
Indexed By Date Previous: Mosaic and ANS Interlock
From: kshores @ cclink . draper . com
Next: Re: mis-use of telnet (was: Re: Hey the crackers have a new twist...)
From: bill @ bhhome . ci . net (Bill Heiser)
Indexed By Thread Previous: mis-use of telnet (was: Re: Hey the crackers have a new twist...)
From: heiser @ world . std . com (Bill Heiser)
Next: Re: mis-use of telnet (was: Re: Hey the crackers have a new twist...)
From: bill @ bhhome . ci . net (Bill Heiser)

Google
 
Search Internet Search www.greatcircle.com