RE: Autonmy Search engine

From: Pybus, David (DPybus@colt-telecom.com)
Date: 01/09/02


From: "Pybus, David" <DPybus@colt-telecom.com>
To: 'JS UK' <freelander3@hotmail.com>
Date: Wed, 9 Jan 2002 15:46:10 -0000 


>Has anybody had any experiance with autonomy search products and/or know of

>any vulnerabilities one should be aware of B4 installing?
>
>Thanx, JS

I used this in a previous job to try and search the net for useful security
information with the intention of writing advisories and the like. I found
it very difficult to get any useful information out of when used in an
Internet as opposed to Intranet environment. It tended to return spurious
information or return a massive generalist FAQ in respone to a very specific
question. A lot less use than the likes of Altavista or Google - which are
free as opposed to £xxxxx. The configuration is anything but intuitive and
the number of times I had to go into immense detail with their support guys
before they'd believe there was even a slight problem wasn't funny.

The worst thing was that it seemed to produce masses of page faults and eat
memory like it was going out of fashion. The box had 512Mb and it was pretty
regular to come in the next morning to find that the Dynamic Reasoning
Engine (DRE) had crashed big time and the system wasn't responding to
queries. Often it would lose memory down a black hole somewhere such that
even killing and restarting all the processes didn't fix the problem and a
re-start was required.

From a purist security perspective the main issues I can remember finding
were that the entire webroot allowed everyone write access, when it only
needed write access to one file for a whiteboard function that in all
probability nobody would ever use. Also you would to check the conf files
for IP address filtering, as you may find that by default anyone who can
connect to the box on the correct port can wipe the entire contents of the
database if they happen to have a copy of the AdminGUI from somewhere.

From a security perspect the only way I would consider running it if you're
worried about security is like this:
        "Intranet"<->FW<->WWW<->FW<->Autonomy<->FW->
Then allow a one way stateful connection from Autonomy to whatever you want
to index.

Good luck, going from experience you will need it.

Kind regards,

David Pybus

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • [Full-Disclosure] Disclosure Debate FW: [ISN] When to Shed Light
    ... Information security, in particular, cannot exist. ... full disclosure results in FEWER hands at work in this process, ... Microsoft because of how dependent publishers are on access to beta software ... > I think actively seeking vulnerabilities is just plain destructive. ...
    (Full-Disclosure)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.security)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.inetserver.iis.security)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Can we prevent IE exploits a priori?
    ... Most all of the IE vulnerabilities that are being ... and the download sites should bring it offline shortly. ... Qwik-Fix Pro is a lot more than simple hardening of the My Computer zone in IE. ... It's an agent based distribution platform for security logic and is inching its ...
    (Bugtraq)