Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: sex, lies, and firewall code
From: Adam Shostack <adam @ homeport . org>
Date: Mon, 27 Oct 1997 11:08:42 -0500 (EST)
To: ryanr @ sybase . com (Ryan Russell)
Cc: proberts @ clark . net, firewalls @ GreatCircle . COM
In-reply-to: <8825653D . 000ED9BA . 00 @ gwwest . sybase . com> from Ryan Russell at "Oct 26, 97 06:56:01 pm"

I've been talking with folks at Security-7 software.  They have
packet filter level code that looks for evil java or activex code.

I asserthat its not a proxy since it does not do rewriting of packets;
it simply blocks those that don't fit its policy model.  (Its policy
tools are pretty cool, allowing you to look at source, destination,
type of code, digital signatures, and function calls within the Java
or ActiveX to make decisions.)

www.security7.com

Adam



Ryan Russell wrote:

| The overall point I've been trying to make (to
| folks who claim otherwise) is that SPFs
| *CAN* filter anything that a AG proxy can.
| I don't claim anything about whether SPFs can
| do it better or worse, or if they do it in current
| implementations, or how much trouble it is
| or isn't to write equivalent code, or any of that.
| Just that they can.

-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume




References:
Indexed By Date Previous: FW: Morningstar PPP for SCO how secure ?
From: Tim Shoemaker <tshoemaker @ normandev . com>
Next: Security Evaluation
From: "Norman Widders" <winspace @ geko . net . au>
Indexed By Thread Previous: Re: sex, lies, and firewall code
From: "Paul D. Robertson" <proberts @ clark . net>
Next: Re: sex, lies, and firewall code
From: "Daniel Wysocki" <DanHu @ bigfoot . com>

Google
 
Search Internet Search www.greatcircle.com