Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Restrict Springboarding
From: Adam Shostack <adam @ homeport . org>
Date: Mon, 9 Jun 1997 07:48:00 -0400 (EDT)
To: Ryan . Russell @ sybase . com (Ryan Russell/SYBASE)
Cc: khanhi @ emirates . com, Firewalls @ GreatCircle . COM
In-reply-to: <199706081622 . JAA00162 @ notesgw2 . sybase . com> from Ryan Russell/SYBASE at "Jun 8, 97 09:28:13 am"

	Your third choice (if management will back you) is to contract
that they won't bounce, use a tty sniffer* to watch their actions, and
then recover damages if they hop on.

	You might also use some form of process accounting to see what
programs they invoke, and challenge them on it.  Install a wrapper
around (telnet, rsh, rlogin, ssh, etc).  Use a restricted shell that
only allows them a certain path, and give them a short list of useful
tools (sed, awk, agrep, ps) to do their work, but nothing else without
asking permission.

	* I say a TTY sniffer because of course you are using an
encrypted telnet to come in over the internet.

	Adam


Ryan Russell/SYBASE wrote:
| Your two choices are to put the hosts they do get
| access to into a DMZ, or to increase security on all
| the other hosts in your network.  In your net, option
| 2 probably isn't practical.
| 
|    Ryan
| 
| ---------- Previous Message ----------

| From: khanhi @ emirates.com (Hidayatullah Khan) @ smtp
| Subject: Restrict Springboarding
| 
| Hello All,
|   Ours is a large organization with a class B addressing. We have a
| firewall in place to allow outgoing web and mail services.  Often we
| have vendors coming in to our systems to support thier applications. Our
| firewall is configured to allow the vendors to telnet to specific hosts.
| On a couple of occasions I have noticed a vendor's presence on a
| different host for which he was not intended to. My question is how can
| we restrict a vendor from "springboarding" (i.e telnetting  to other
| machines on our network) from the actual specific host.  
| Thanks in Adv,
| Khan


-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume




References:
Indexed By Date Previous: Re: nt web server log
From: Ian Miller <firewalls @ scientia . com>
Next: RE: ISP Connection
From: "John Kemker" <john . kemker @ pfsfhq . com>
Indexed By Thread Previous: Re: Restrict Springboarding
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Next: RE: Restrict Springboarding
From: "Adams, Gavin" <gadams @ ccscns . com>

Google
 
Search Internet Search www.greatcircle.com