RE: Authentication Vulnerability in NetScreen ScreenOS

From: Brian Soby (tmpbox5_at_hotmail.com)
Date: 06/26/03

  • Next message: Hugo van der Kooij: "RE: Authentication Vulnerability in NetScreen ScreenOS"
    To: bugtraq@securityfocus.com
    Date: Thu, 26 Jun 2003 17:37:53 +0000
    
    

    >However, after a user is authenticated, anyone else may also access the
    >protected services if they orginate from the same source IP address (NAT'd
    >network). The authentication mechanism is designed to authenticate based on
    >source-ip address only.

    Most firewalls track authenticated users based on the client's source IP
    address. If you need a stronger method, you could always use the Netscreen
    Remote client software and require a secure tunnel from the clients to get
    to your protected resources.

    -Brian Soby

    _________________________________________________________________
    The new MSN 8: advanced junk mail protection and 2 months FREE*
    http://join.msn.com/?page=features/junkmail


  • Next message: Hugo van der Kooij: "RE: Authentication Vulnerability in NetScreen ScreenOS"

    Relevant Pages

    • Re: Erasing an OTP file on a SD card.
      ... >> AES is the main protection, and OTP will not do the AES weaker. ... The keys are collected when the user writes randomly over the handheld ... If you don't have a secure way to protect the authentication process, ...
      (sci.crypt)
    • Re: How to securely publish a Click Once application
      ... the folder hierarchy in tact. ... Forms authentication, deny all anonymous users and the mime setting to add ... non-asp.net apps to the forms authentication protection looks like the right ... for any updates - but because the update location doesn't allow ...
      (microsoft.public.dotnet.framework)
    • Re: allow selective RSA AUTH in sshd setup?
      ... > certainty: a user will know enough to set up authentication from his ... Using RSA keys gives you two factors of protection. ... > server is beyond my ability, ...
      (FreeBSD-Security)
    • Re: Forms Authentication only displays login.aspx
      ... I can not get forms authentication to work. ... false);} else {// not a valid login. ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: Forms Authentication only displays login.aspx
      ... I can not get forms authentication to work. ... false);} else {// not a valid login. ...
      (microsoft.public.dotnet.framework.aspnet)