Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Http and security
From: rachelr @ ejv . com (Rachel Rosencrantz)
Date: Fri, 20 Oct 95 11:05:12 EDT
To: Firewalls @ GreatCircle . COM
Reply-to: rachelr @ pobox . com

        From: jhb @
 sun811 .
 npt .
 nuwc .
 navy .
 mil (John Balch)
	Subject: Web Server Security

	I've seen items about security holes in Web servers on this list and
	elsewhere, but I need detailed information on a particular point.

	Is it possible to break into a server that only carries HTML documents
	through links to those documents on a Home Page on another server?

	          |
	          |       Firewall,         Server 'A'   HT link     Server 'B'
	 Internet |-----   router   -----    with Home  ---------       with
	          |                            Page                  HTML docs
	          |
	    
	In other words, is Server 'B' protected by firewalled Server 'A' because
	Server 'B' doesn't have a home page, or does that not make any difference?


Well the problem with this, unless more recent revs of Mosaic and Netscape and 
etc. have changed things, is that in order to get to Server B's HTML docs
one of 2 things have to be happening. 
1) Server B's documents have to be exported to Server A (ala NFS etc.).
or:
2) Server B is running httpd to allow other machines to acess the web documents.

Solution 1 has all of the inherent problems of exporting files. Solution
2 essentially makes server B a web server too, although
a slightly behind the scenes one. You can block all services except
document retrieval on server B (eg. no cgi-scripts), but httpd is still
running so the weakness still exists.

A "Home Page" is really just an HTML document.  There is usually 
a default html document that your httpd gives to users when 
someone calls up http:/www.yourserver.com, but a "home page" is not 
intrinsicly different than any other html doc. 

-Rachelr


Follow-Ups:
Indexed By Date Previous: Re: Netscape (oh noooo)
From: Mats Bredell <Mats . Bredell @ udac . se>
Next: Re: Encrypted data across national boundaries
From: rachelr @ ejv . com (Rachel Rosencrantz)
Indexed By Thread Previous: anonymous mail
From: Martine Gross <Martine . Gross @ lri . fr>
Next: t-3+++ firewalls
From: Christopher Osborn <cosborn @ bbn . com>

Google
 
Search Internet Search www.greatcircle.com