Remote File include (RFI) vulnerabilities



Hi,

I am using IntruPro-IPS to protect both servers and clients. It seems
to be flagging RFI related anomalies for traffic going from internal
clients to servers in Internet. I thought these attacks need to be
detected only if the internal servers are being attacked. That is, I
think that RFI detection is needed for server protection.

is it necessary to check the internal client traffic, that is, is this
needed for client side protection. Any reasons?

thanks
Ravi

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Spliting traffic between two NICs
    ... We have a bunch of servers on our network, each with one NIC in them, ... and a large number of thin clients connect to any of these servers. ... I intend to send all internet ... sysadmin at handsworth dot bham dot sch dot uk ...
    (comp.os.linux.networking)
  • Re: Restrict Dynamic Updates
    ... exposed to the Internet is an inherently bad idea, but am in a position where ... my thought was to leave the clients pointing to the BIND/DNS ... servers to resolve all non-AD queries and redirect them to the AD/DNS servers ... internal DNS server host external public data. ...
    (microsoft.public.windows.server.dns)
  • Re: USERS UNABLE TO GET TO WEBSITES
    ... What IP' are used for the clients? ... > DHCP Server sends them DNS entries for 2 internal servers only. ... They have a straight shot to the internet ...
    (microsoft.public.win2000.active_directory)
  • Re: Remote File include (RFI) vulnerabilities
    ... I am using IntruPro-IPS to protect both servers and clients. ... clients to servers in Internet. ... think that RFI detection is needed for server protection. ... needed for client side protection. ...
    (Focus-IDS)
  • Re: Browsing in multiple domains
    ... servers a common point of registration so that the "Browse Masters" ... Browsing uses NetBIOS; AD uses DNS ... Point ALL clients, including DCs and the WINS servers to these WINS ... If you wish to resolve the Internet, have the internal DNS server "forward" ...
    (microsoft.public.win2000.active_directory)