[fw-wiz] X server in a Firewall



Taking in account that a graphical interface is a
requirement, from a risk standpoint, what is the
problem in running a X server (using local IPC, no
external port) in an unix based firewall box to manage
it (using a gtk interface, for exemple)?

Managing it trough a ssh port (or a web interface or
another port used by a proprietary console) wouldn't
increase the risk? since the ssh daemon (or web
server, etc) could be vulnerable and, even if is only
accepting connections from a specific IP, someone on
internal network could do ARP spoofing or something.

Besides this, the box managing the firewall could have
a key logger installed. (I know, in an ideal
world...).








__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Long Time Samba No Work-Need Expert Help On Samba/Networking
    ... The windows firewall has to be completely ... I tried the samba commands I listed on the ... added interface ip=127.0.0.1 bcast=127.255.255.255 ... server string = %h server ...
    (Ubuntu)
  • Re: [Debian-User] Xen
    ... I've successfully re-implemented my home server using xen, ... Okay, Dom0 is on the LAN and serves up music, video, photos and pulls ... DomU1 is my firewall running a standard 3 interface ...
    (Debian-User)
  • Defining Multiple internal interfaces in my firewall
    ... I am using a linux box as a firewall, router, and ppp server. ... basically have 2 machines that I am connecting, a server and a client. ... This generates the interface ppp0, ...
    (comp.os.linux.networking)
  • Re: Witch cisco router to route 100 mbit internet?
    ... I just want a normal defualt cisco router that supports 100mbit ... Your routing is being done at the server farm most likely. ... You will plug the ethernet cable provided to you from the server farm to the firewall and configure the firewall's interface as outside, then you take another patch cable and plug it from the firewall to the server you are using and configure that interface to be the inside interface. ...
    (comp.dcom.sys.cisco)
  • Re: What doesnt lend itself to OO?
    ... The whole idea that a subsystem is just ... > The first line exists in the server. ... objects between client and server i.e. as far as the client code is ... > external interface is the traditional input interface whose ...
    (comp.object)