Re: [fw-wiz] Web Server Monitoring

From: Paul Robertson (proberts_at_patriot.net)
Date: 09/14/03

  • Next message: Chuck Swiger: "Re: [fw-wiz] Sniffing DSL Connection"
    To: Tony Turner <tnyturner@mindspring.com>
    Date: Sun, 14 Sep 2003 12:45:35 -0400 (EDT)
    
    

    On Fri, 12 Sep 2003, Tony Turner wrote:

    > We have several web servers that we support throughout the southeast.
    > We usually use VNC. I have a few questions for you. How secure is VNC
    > and what are some known security risks. What is the best way to monitor

    It isn't, perhaps you should read the documentation which comes with VNC,
    which (at least last I cheked) had a section on how it wasn't secure. I
    believe the authors recommended running it over SSH tunnels.

    > these servers? have used large scale monitoring tools that create
    > tickets whenever a server or a switch stops responding, but this was all
    > on the same network. I am looking at a program called Networkview.
    > This product gives me a GUI interface with all of my sites and let's me
    > know which are up or down. It will also email me if something goes
    > down. It seems that it works great locally, but I need something that I
    > can use over the Internet. Networkview will ping these IP addresses,
    > but most of these webservers are behind routers or firewalls that block
    > ICMP. WIll SNMP work over the internet and is it really necessary to
    > block ICMP. How hard is SNMP to set up and where do I start?

    SNMP is a secuirty nightmare, and you really, really don't want to expose
    current implementations to the Internet at large. If you're worried about
    Web services, grab a page every few minutes, and alert on errors for that,
    there are plenty of tools to do so, and writing one isn't all that
    difficult either.

    While out-of-band monitoring is generally a good thing, it's only a good
    thing when the channel is private. If you're going to use a public
    channel, then do in-band monitoring, since you *have* to expose HTTP to
    the world anyway, using it to check the status isn't the increase in risk
    that trying to do some other protocol is.

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    proberts@patriot.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Chuck Swiger: "Re: [fw-wiz] Sniffing DSL Connection"

    Relevant Pages

    • RE: PCanywhere: security of it and operation over DSL/cable modem s
      ... I work for Expertcity, the company that makes GoToMyPC, so you might want to ... Subject: PCanywhere: security of it and operation over DSL/cable ... then x-forwarding the *nix version of VNC that connects to the windows ... that's less secure again. ...
      (Security-Basics)
    • Re: Have I been hacked Windows Server 2003?
      ... What I know is that VNC only encrypts password, ... The only really secure computer is one without a network. ... characters long password is not necessary secure. ... characters are automatically stored as NTLM Hash). ...
      (microsoft.public.windows.server.security)
    • RD works via lan but not via internet
      ... On Windows 2000 computers vnc works fine. ... found (lan), remote (internet) logons are not found in the log. ...
      (microsoft.public.windowsxp.work_remotely)
    • Security of OpenSSH versus PCAnywhere; GoToMyPC
      ... PCAnywhere or VNC over a ... Now I will need to be on the internet using a Window PC, ... I believe I should be able to set up a OpenSSH tunnel on the internet ... I was wondering if anybody has any thoughts on the security ...
      (comp.security.ssh)
    • Re: Remote access solution
      ... >I've always recommended tunneling the whole VNC session through some type ... Actually, I don't think even the initial authentication is secure, you ... I'd say tacking a vpn on top would be a good idea. ...
      (Security-Basics)

    Loading