Re: [fw-wiz] X server in a Firewall



John M wrote:
> On remote access:
>> Web servers tend to increase the risk, as does any
>> remote technology.
>
> OK. But what is your recommendation to a fortune 500
> company? :)
>
> That is, if Coca-Cola wanted a unix based firewall and
> _wanted manage it trough a graphical interface_, what
> would you suggest? A X server running in a firewall
> sounds bad, but a web server or ssh server could be
> even worse (key logger on the management station or
> buffer overflow in the ssh or web daemon and both run
> as root, so to have permission to change the fw rules)

In terms of their security history, OpenSSH isn't perfect, but comparing it to
X11 is pretty amusing. Which one would you rather audit for poorly written
code, potentially exploitable buffer overflows, and other security vulnerabilities:

5-pi% cd /usr/ports/distfiles && ls -lh openssh-4.2p1.tar.gz xorg/X11R6*
-rw-r--r-- 1 root wheel 893K Sep 1 02:30 openssh-4.2p1.tar.gz
-rw-r--r-- 1 root wheel 31M Feb 25 2005 xorg/X11R6.8.2-src1.tar.gz
-rw-r--r-- 1 root wheel 3.8M Feb 25 2005 xorg/X11R6.8.2-src2.tar.gz
-rw-r--r-- 1 root wheel 9.9M Feb 25 2005 xorg/X11R6.8.2-src3.tar.gz

...?

--
-Chuck
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Please Help
    ... > Go to the thread called Newbie Questions and look at David's post. ... >> installed a firewall, and behind it is twenty windows 2000 machines. ... It looks like to me i can also put these two web servers behind the ... Is there any simple way to protect web servers? ...
    (comp.security.firewalls)
  • Re: multiple IIS server boxes behind firewall
    ... Multiple external IPs is one option. ... > firewall, based on rule it was redirected then to static private IP in dmz ... > now I have a need to add more web servers to dmz with web ...
    (microsoft.public.inetserver.iis)
  • Re: hardware firewall recommendation
    ... We have 2 web servers to protect. ... My main needs are a configurable firewall. ... Calling an illegal alien an "undocumented worker" is like calling a ...
    (comp.security.firewalls)
  • Re: IIS / SSL + Pages not Loading (HTTPS)
    ... Is there a way to get the common name from the machine? ... >>have made changes to the Load Balancer recently for SSL Sticky Sessions ... what it could be is the Firewall as we havent ... > load-balancer and mutliple identical web servers all serving up SSL ...
    (microsoft.public.inetserver.iis.security)
  • Re: Help! Can I do this for under $400?
    ... Unless, I miss some something, a key firewall functionality, address ... filtering, is missing. ... destination addresses and port numbers. ... We have 3 web servers on the LAN ...
    (comp.security.firewalls)