Re: [fw-wiz] Rationale of the great DMZ

From: Steven M. Bellovin (smb@research.att.com)
Date: 07/13/02


From: "Steven M. Bellovin" <smb@research.att.com>
To: Paul Robertson <proberts@patriot.net>
Date: Sat Jul 13 11:11:01 2002

In message <Pine.LNX.4.44.0207101323470.23014-100000@adams.patriot.net>, Paul R
obertson writes:

>I've always been of the opinion that stats should be gathered off the
>network by a machine that doesn't have transmit capability (either the
>cable doesn't have a TX wire, or the Ethernet driver for the listening NIC
>doesn't have that code.)

There are actually commercial devices to do that -- the FBI uses one
with Carnivore...

                --Steve Bellovin, http://www.research.att.com/~smb (me)
                http://www.wilyhacker.com ("Firewalls" book)



Relevant Pages

  • Re: Email Pen-testing
    ... In my opinion, social engineering is part of a pentest. ... etc. all your hardening isn't it worth. ... Also, it is often the easiest way, to brake into the companies network, ... that email worms are often making its way inside a company ...
    (Pen-Test)
  • Re: RRAS configuration
    ... My personal opinion is that if all your network is reachable from the ... It is the simplest routing setup because the firewall is already the ... > VPN server and connecting to it then the network behind it. ...
    (microsoft.public.windows.server.networking)
  • Re: OT:Mickey Mouse Names The Villain
    ... People are so sure that if someone has an opinion, it's because it's "their team's" opinion. ... That it has to be partisan, because _everybody_ is partisan, and hates "the other guys." ... But there _is_ such a thing as objective truth, and propaganda pieces like this make it harder for the _average_ person, of _average_ intelligence, and who has exposure to _average_ sources of information, to tell the difference between fact and fiction. ... If your solution is what you mentioned earlier--protesting to the network and Disney and ABC's other advertisers--I'm fine with that too. ...
    (rec.arts.tv.soaps.abc)
  • Re: Internet Usage
    ... I was able to access it through the ip address and there are some stats - ... High speed telephone line and networks card hooked into gateway ... I have seen many applications that monitor all network traffic (EG: ... Either way you can access these statistics with a little VB programming. ...
    (microsoft.public.vb.general.discussion)
  • Re: Long logon times (and other associated issues)
    ... >> stats? ... > connection, so I cannot say whether this is slow, fast or normal. ... it does seem to be some kind of network related thing. ... resetting or upgrading the bios has ...
    (microsoft.public.windowsxp.network_web)

Quantcast