Great Circle Associates Firewalls
(February 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Plodigy
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Date: Fri, 17 Feb 95 12:04:31 -0500
To: "firewalls @ greatcircle . com"@UVS1.dnet.mmc.com

Robert Moskowitz rites:

>I strongly doubt if someone can gain access to our network while an employee
>is dialed into Prodigy :)

"Blem wit" this is "how do you ensure that the employees only dial *P* ?"
- a modem pool with a limited number of allowed connections ? Why pay
by the hour ?

>And exactly what has been the real exposure of Web Browsers (not just
>theoretical non-paranoid Ghostwriter viewing of Postscript docs with nasty
>imbedded commands).

HTTP also contains the capability for embedded commands and execution, Look
at the recent CERT advisory on the web language for more detail.

						Warmly,
							Padgett

ps of course if a gift-wrapped #2-3 Facel-Vega HK-500 (Chrysler drivetrain) 
   should happen to appear at my door, I would be happy to take some vacation 
   and design a proper perimeter defense 8*).

Indexed By Date Previous: Re: questions about security & WWW browsers
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: Kevin Mitnick
From: patrick @ oes . amdahl . com (Patrick Horgan)
Indexed By Thread Previous: Prodigy as a secure interface to the web?
From: rgm3 @ is . chrysler . com (Robert Moskowitz)
Next: Kevin Mitnick
From: patrick @ oes . amdahl . com (Patrick Horgan)

Google
 
Search Internet Search www.greatcircle.com