Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Anti Satan Tool
From: "Frank Byrum" <byrum @ vbv . dec . com>
Date: Fri, 31 Mar 95 13:22:23 -0500
To: firewalls @ greatcircle . com
Cc: byrum @ vbv . dec . com
In-reply-to: Your message of "Fri, 31 Mar 95 12:07:59 EST."

Another Frank writes:
>Up I go onto the soapbox --- feel free to hit the "Delete" button.
>
>The *best* Anti Satan tool is implementing the correct security discipline
>on Internet hosts in the first place.  Satan does nothing that can't be
>stopped with known, publicized techniques.  The next 5 days are better
>spent fixing known, long festering problems than setting up a tool that
>proports to "detect" Satan "attacks."
>
>Down I go off the soapbox and back into the salt mine.

I must agree.  If you look at the SATAN manual, it really just checks
for things that are already known.  And one should review their security
policy and audit their own site every so often anyway.  The things that 
it looks for in a hevay probe can be fixed by either upgrading your
software or reconsider what you running on your machine. 

IMHO I think that SATAN is just the beginning of better tools and I
expect to see more (including some additions to SATAN)...  No Security
Tool will replace a well defined and implemented security policy.  And
periodically auditing what you have defined and implemented.  

Otherwise things go to entropy.  

Frank

Indexed By Date Previous: Re: Microsoft SMTP Gateway
From: matt @ uts . EDU . AU (Jas (Matthew K))
Next: Re: Alarms and paging
From: "Alastair Young" <alastair @ cadence . com>
Indexed By Thread Previous: Re: Anti Satan Tool
From: rmck @ sandfiddler . paragon-systems . com (Bob McKisson)
Next: How to detect SATAN surfing attempts ?
From: "Vincent D. Skahan" <vds7789 @ aw101 . iasl . ca . boeing . com>

Google
 
Search Internet Search www.greatcircle.com