Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Does Winframe need a firewall?
From: Adam Shostack <adam @ homeport . org>
Date: Fri, 6 Jun 1997 09:50:05 -0400 (EDT)
To: kgunther @ nassau . cv . net (Ken Gunther)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <3 . 0 . 1 . 16 . 19970605220043 . 356f0950 @ mail-hub> from Ken Gunther at "Jun 5, 97 10:00:43 pm"

If I get an account on IGN, what prevents me from attacking your
Winframe box?  Do you trust Citrix to have gotten all their security
right?  What can I gain once I've broken it?  (Hints; does it
strongly* encrypt passwords as they go over the net?  Does it resist
password guessing attacks?  Session hijacking?)

*For explanations of strong encryption, see the Snake Oil Crypto FAQ.

http://www.research.megasoft.com/people/cmcurtin/snake-oil-faq.html

Adam

Ken Gunther wrote:
| 	We are currently using Winframe by Citrix to give remote users access to
| applications at our datacenter. Access to the Winframe box is through the
| IBM Global Network (IGN). IGN is a subscribers only network. It is not as
| open as the Internet but by no means do we have control over who is on it. 
| 
| 	We currently have a firewall in front of the Winframe box but there is a
| noticable delay in keystrokes when going through the firewall (TIS Toolkit
| on a Linux box). We have performed some tests where for short periods of
| time the Winframe box was connected directly to the IGN and the keystroke
| delays went away. 
| 
| 	Is Winframe safe to put directly on the untrusted network? We are worried
| about unauthorized people getting through to the trusted side as well as
| denial of service attacks where people try to crash Winframe.


-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume




References:
Indexed By Date Previous: RE: [FW1] Out of Band Data Attack against NT-Hosts
From: "Jim E. Crawford" <jcrawford @ wilcom . net>
Next: Does Winframe need a firewall?
From: Steve Gaarder <gaarder @ actech . com>
Indexed By Thread Previous: Does Winframe need a firewall?
From: Ken Gunther <kgunther @ nassau . cv . net>
Next: Does Winframe need a firewall?
From: Steve Gaarder <gaarder @ actech . com>

Google
 
Search Internet Search www.greatcircle.com