Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Modem hacking
From: bobk @ manzanita (Bob Konigsberg)
Date: Mon, 9 Sep 1996 17:19:55 -0700
To: rruda @ osti . com
Cc: firewalls @ greatcircle . com

My concerns are:

1) Remote PC, PC Anywhere (and similar products), someone could guess the password
or worse the system doesn't have a password.  Once in, they're on your net
completely around any other barriers put up on the outside.

2) Some PC packages can be configured to route IP traffic.  There are people
who consider their personal connectivity to be more important (to them) than
any security considerations someone else (like management) might have.

3) I don't mind dial-out capability only.  If people really need this, then
I recommend a modem pooling solution where dial-ins are met with either no
answer, or a secured login prompt of some sort administered by people who
know what they are doing.

As a backup proposition (meaning if you HAVE to allow dial-ins), then set the
modem to not answer until 10 or 12 rings.  This is VERY WEAK security, but it
will generally not answer demon-dialers which give up after 3-5 rings.

In addition, get a demon-dialer yourself, and scan all incoming phone lines
on a regular basis, and when you find modems that answer the phone, contact 
the owner/operator of said modem, and insist that they beef up their security.

BobK

Indexed By Date Previous: secure http proxy?
From: nsaputra @ HEA . COM (Nancy Saputra X8387)
Next: RE: FreeBSD Firewall Package
From: "David J. Taylor" <Dave @ insweb . com>
Indexed By Thread Previous: Re: Modem hacking
From: Moroni <moroni @ scranton . com>
Next: Re: Modem hacking
From: harker @ harker . com (Robert Harker)

Google
 
Search Internet Search www.greatcircle.com