Great Circle Associates Firewalls
(April 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: WWW proxy information
From: francis @ avalle . insoft . com (John [Francis] Stracke)
Date: Tue, 26 Apr 1994 11:03:41 +0500
To: firewalls @ GreatCircle . COM
In-reply-to: Kevin Altis's message of Mon, 25 Apr 1994 16:42:36 -0800 <m0pvaF9-0003UqC @ ibeam . intel . com>

>Since February, 1994, firewalls have been "safely permeable" for World Wide
>Web (WWW) clients via an application level proxy. Proxy support is built

"Safely"? I don't think so.  There was some talk a while ago on this
list about mosaic (and, perhaps, lynx) having serious security holes.
Something about using system() indiscriminately, something like:

{
  char cmd[1024];
  sprintf(cmd,"more %s",filename);
  system(cmd);
}

where filename is provided by the http page you're reading.  If
filename is "foo ; otherCmd", first you see what you expect, then
otherCmd is executed *as you*.  With some trickiness, otherCmd can be
used to compromise your system, or at least your own account, and send
a notification to the slime who wrote it.

>If you have concerns about application level proxies in general or our
>solution specifically, then please raise them on this list rather than
>emailing me directly so that we can all participate in the discussion.

I think there's (likely) nothing wrong with your proxy; but people
need to realize that running a proxied mosaic is scarcely safer than
running without a firewall.

/===========================================================================\
|John (Francis) Stracke  | My opinions are my own.| The cheapest, fastest,  |
|InSoft, Inc.            |========================/  and most reliable      |
|Mechanicsburg, PA       | components of a computer system are those that   |
|francis @
 insoft .
 com      | aren't there.--Gordon Bell                       |
\===========================================================================/


Follow-Ups:
References:
Indexed By Date Previous: RE: Distributed Object security ?
From: jim @ Tadpole . COM (Jim Thompson)
Next: Re: Cost of firewall hosts; BSDI Unix
From: Marcus J Ranum <mjr @ tis . com>
Indexed By Thread Previous: WWW proxy information
From: altis @ ibeam . intel . com (Kevin Altis)
Next: Re: WWW proxy information
From: Tim Guarnieri <timg @ mv . us . adobe . com>

Google
 
Search Internet Search www.greatcircle.com