Great Circle Associates Firewalls
(August 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Screening & routers
From: z056716 @ uprc . com (LaCoursiere J. D. (Jeff))
Date: Thu, 4 Aug 1994 10:22:42 +0800
To: brent @ GreatCircle . COM, mkellis @ ritz . mordor . com
Cc: quent . johnson @ Intellistor . COM, firewalls @ GreatCircle . COM

> > One thought makes me really nervous about this approach: what if the
> > authenticating gateway is compromised?  Then you can rlogin from there
> > to the inside, with no passwords on the inside.
> 
> True, but it does solve one of the associated problems with the telnet
> to firewall, then telnet into the site, passing one's (presumably)
> cleartext password inside while you go.  Unless you have encrypted
> telnet to the firewall, your password's still in the clear from
> your (Internet based) originating station to the firewall, so being able
> to 'hide' your password by using rlogin could be a benefit.
> 
> In the best of all worlds, both the bastion and the internal
> hosts would have something like S/key, but assuming that only the firewall's

Hmmm.  What about a drop-in replacement for telnetd on inside machines that
would use s/key (or whatever) if the source was the bastion host, but used
regular passwords for internal telnets...


        ______/   Jeff LaCoursiere                   FastLane Communications
       /          Network security/services          mail info @
 fl .
 uprc .
 com
      ___/        lacoursj @
 uprc .
 com
     /
  __/  ASTLANE  Communications!  Connecting America to the Internet...
        


Follow-Ups:
Indexed By Date Previous: Re: mount from Internet
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>
Next: (fwd) Intrusion Detection Systems Mailing List (OPEN)
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)
Indexed By Thread Previous: Re: Screening & routers
From: Michael Ellis <mkellis @ ritz . mordor . com>
Next: Re: Screening & routers
From: "Daniel O'Callaghan" <danny @ cwis . unimelb . edu . au>

Google
 
Search Internet Search www.greatcircle.com