Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: WebStalker
From: Ken Roy <kenr @ mail . fermc . or . jp>
Date: Wed, 23 Jul 1997 17:54:15 +0100
To: Firewalls <firewalls @ GreatCircle . COM>, Timothy Scott <tscott @ laurel . ocs . mq . edu . au>
References: <1 . 5 . 4 . 32 . 19970721223956 . 006998e4 @ laurel . ocs . mq . edu . au>

Timothy Scott wrote:
> 
> Morning all,
> What do people think about Haystack Labs' "WebStalker"?
> Tim.
I am a Network Security Specialist and have evaluated both the Solaris
and Win NT version of WebStalker.  It's a nice idea, however it does not
function properly.  For instance, in order to stop users from "jumping"
(i.e., telnet or ftp from the Web Server to another computer) WebStalker
monitors ftp and telnet executables.  Of course merely changing the name
of the executables easily by-passes this security (which I have tested
and verified). WebStalker is also supposed to monitor designated files
and directories.  However, even though it successfuly informs the
Administrator that a file was changed, it should not have allowed the
file to be changed in the first place.

What I've noticed is that WebStalker is always one step behind the
operating system and not one step in front of the OS. It also does not
change file attributes to match the security profile.  That is, when the
Administrator configures WebStalker to allow certain users to change
files at certain times, WebStalker does not change the file permissions
of the protected files.  

I don't think WebStalker is ready yet.  It should be written into the OS
instead of outside the OS.

Ken


Follow-Ups:
References:
  • WebStalker
    From: Timothy Scott <tscott @ laurel . ocs . mq . edu . au>
Indexed By Date Previous: sng ptelnetd problem
From: chris sieber <sieber @ Colorado . EDU>
Next: Re: About sendmai
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Indexed By Thread Previous: WebStalker
From: Timothy Scott <tscott @ laurel . ocs . mq . edu . au>
Next: Re: WebStalker
From: Brian Mitchell <brian @ firehouse . net>

Google
 
Search Internet Search www.greatcircle.com