Re: [fw-wiz] Outlook Web Access - Paranoid?
From: Mikael Olsson (mikael.olsson@clavister.com)
Date: 11/28/02
- Next message: Paul D. Robertson: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- Previous message: Frank Knobbe: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- In reply to: Christopher Lee: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- Next in thread: Paul D. Robertson: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Mikael Olsson <mikael.olsson@clavister.com> To: Christopher Lee <complexity@bigfoot.com> Date: Thu Nov 28 19:42:01 2002
Christopher Lee wrote:
>
> While the number of RPC ports one must open to allow OWA(or any MS DCOM apps)
> to work is insane, that doesn't mean you have open them manually. Check Point
> firewall (for example) has the smarts to be able to open them dynamically as
> needed. This way, unless the intruder is able to forge the same DCOM/RPC
> communications, the exposure is not all that bad...
Ah, yes, and such mechanisms are of course entirely impossible to fool
into opening up arbitrary ports of the attacker's choice. </sarcasm>
Fortunately, the set of RPC ports used can be reduced. And, quite
frankly, if I have to do RPC through a firewall (yuck, argh, ptooiiee),
I'd rather have a manageable small set of static holes open than
some Black Magic figuring it out for me.
More info about this at:
http://support.microsoft.com/default.aspx?scid=KB;en-us;q154596
"HOWTO: Configure RPC Dynamic Port Allocation to Work with Firewall"
-- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com
- Next message: Paul D. Robertson: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- Previous message: Frank Knobbe: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- In reply to: Christopher Lee: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- Next in thread: Paul D. Robertson: "RE: [fw-wiz] Outlook Web Access - Paranoid?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|