Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Web Browser-Firewall Question (fwd)
From: Frank Wortner <frank @ prodigy . com>
Date: Tue, 31 Jan 1995 10:35:51 -0500 (EST)
To: "Dr. Frederick B. Cohen" <fc @ all . net>
Cc: Firewalls @ greatcircle . com
In-reply-to: <199501302353 . SAA02431 @ all . net>

On Monday, 30 Jan 1995, Dr. Frederick B. Cohen wrote:

> 	The real problem you will encounter is likely that W3 is not
> secure.  For example, .ps files which alter internal files will pass
> throuhg the firewall to the W3 browser and cause internal damage.
> 

The problem you describe isn't limited to W3 browsers.  In fact, *any* 
system which allows the blind invocation of programs is vulnerable.  One 
could just as well send the PostScript "nastygram" you describe through 
email.  An email user agent that "conveniently" started a PostScript 
viewer would basically defer any security policy enforcement to the 
viewer just as effectively as a W3 browser.

Now, most sites don't ban email, so vigilance against malicious or 
accidental damage can't just rely on a perimeter firewall.  The "hard 
crunchy shell surrounding a soft chewy center" does not provide automatic 
protection against all attacks --- just ask your average armadillo how 
safe it is once a predator has discovered how to turn it over. ;-)

					Frank

--
"Outside of a dog, a book is a man's best friend;
 inside of a dog, it's too dark to read."  -- Groucho Marx



References:
Indexed By Date Previous: Re[2]: Router filtering not enough! (Was: Re: CERT advisory
From: "Nayfield, Rod" <rnayfield @ mail . IConNet . COM>
Next: Re: One routing from the internal net to the firewall
From: ylee @ syl . dl . nec . com (Ying-Da Lee)
Indexed By Thread Previous: Re: Web Browser-Firewall Question (fwd)
From: "Dr. Frederick B. Cohen" <fc @ all . net>
Next: RE:Re: Web Browser-Firewall Question (fwd)
From: "Tim Tuck" <tim_tuck @ yes . optus . com . au>

Google
 
Search Internet Search www.greatcircle.com