Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: [NTSEC] ActiveX, MSIE and Quicken
From: "Starkweather, Mike" <mike . starkweather @ anheuser-busch . com>
Date: Mon, 10 Feb 1997 10:41:33 -0600
To: "firewalls @ GreatCircle . COM" <firewalls @ GreatCircle . COM>
Cc: "Starkweather, Mike" <mike . starkweather @ anheuser-busch . com>

Using the firewall to filter ActiveX and Java is like throwing out the 
baby with the bath water.  This sounds more like a macro virus than a 
Internet exploit.  Wouldn't it be better to treat it at the desktop 
instead of the firewall?

Mike Starkweather

----------
From:  Jerry Mendes[SMTP:mendes @
 garnet .
 berkeley .
 edu]
Sent:  Saturday, February 08, 1997 5:05 AM
To:  Russ
Cc:  firewalls @
 GreatCircle .
 COM
Subject:  RE: [NTSEC] ActiveX, MSIE and Quicken

Presumably, one answer is for the firewall companies to write 
additional
application layer filters for port 80, looking for ActiveX or Java
downloads.  This would make configuration of the firewall a bit more
complex.  Don't know if any of 'em are considering this yet.  Anyone 
have
any scoop on this?

Jerry Mendes, Principal Consultant
DataComm Insights
150 Seminary Drive
Mill Valley, California  94941

Voice:  415-381-5500
FAX:    415-381-5502
Email:  mendes @
 garnet .
 berkeley .
 edu

At 11:40 PM 2/1/97 -0500, Russ wrote:
>To try and keep this on a Firewalls vein. The tunneling of anything 
over
>HTTP is, in my opinion, the crappy technology. That goes for Java
>applets or certificate authentication for that matter. I don't like 
the
>idea of combining diverse tasks within a single channel if its 
possible
>to avoid it, and it is possible, so the only reason its not being 
done
>is to USURP FIREWALLS.
_______________________________________________________________________  
_____
_______
Jerry Mendes, Principal Consultant              Voice:   (415) 
381-5500
DataComm Insights                               FAX:     (415) 
381-5502
150 Seminary Drive                              Email:
mendes @
 garnet .
 berkeley .
 edu
Mill Valley, California  94941




Follow-Ups:
Indexed By Date Previous: Re: SUN's Stealth Product
From: peter . gregory-unix @ mccaw-stg . com (Peter Gregory)
Next: Re: SLr* released. rsh,rcp,rdist over SSL
From: peter @ baileynm . com (Peter da Silva)
Indexed By Thread Previous: RE: [NTSEC] ActiveX, MSIE and Quicken
From: "William M. Perry" <wmperry @ aventail . com>
Next: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Bob Beck <beck @ obtuse . com>

Google
 
Search Internet Search www.greatcircle.com