Re: F5 and similar

From: Paul R (paul_at_sesamedata.net)
Date: 08/27/03

  • Next message: Gareth Bromley: "Re: F5 and similar"
    To: "pen test" <pentestlist@hotmail.com>, <pen-test@securityfocus.com>
    Date: Wed, 27 Aug 2003 15:27:45 +0100
    
    

    You probably already know this but by signing up for an account in the
    support section you will get a great deal more access to their site
    documentation.
    Cheers, Paul

    ----- Original Message -----
    From: "pen test" <pentestlist@hotmail.com>
    To: <pen-test@securityfocus.com>
    Sent: Wednesday, August 27, 2003 2:55 AM
    Subject: F5 and similar

    > Recently I started a pen test of a network and the company is using a F5
    > BigIP for load balancing and ssl acceleration. I looked and looked and
    > could not find any information to answer a few questions. Any help would
    be
    > great.
    >
    > Does the BigIp handle all requests and stay between the client and server
    or
    > does it just simply redirect to the server?
    >
    > Bascially what I am getting at is if the the BigIp is between the client
    and
    > application server
    >
    > client ---ssl--- bigip ---http--- application server
    >
    > is the the application server safe from attacks that may affect it as the
    > bigip will actually be on the one that is attacked?
    >
    > Thanks
    >
    > _________________________________________________________________
    > Get MSN 8 and enjoy automatic e-mail virus protection.
    > http://join.msn.com/?page=features/virus
    >
    >
    > --------------------------------------------------------------------------
    -
    > FREE Trial!
    > New for security consultants and in-house pros: FOUNDSTONE PROFESSIONAL
    > and PROFESSIONAL TL software. Fast, reliable vulnerability assessment
    > technology powered by the award-winning FoundScan engine. Try it free for
    21 days at: http://www.securityfocus.com/sponsor/Foundstone_pen-test_030825
    > --------------------------------------------------------------------------

    --
    >
    >
    >
    >
    ---------------------------------------------------------------------------
    FREE Trial!
    New for security consultants and in-house pros: FOUNDSTONE PROFESSIONAL 
    and PROFESSIONAL TL software. Fast, reliable vulnerability assessment 
    technology powered by the award-winning FoundScan engine. Try it free for  21 days at: http://www.securityfocus.com/sponsor/Foundstone_pen-test_030825
    ----------------------------------------------------------------------------
    

  • Next message: Gareth Bromley: "Re: F5 and similar"

    Relevant Pages

    • F5 and similar
      ... BigIP for load balancing and ssl acceleration. ... does it just simply redirect to the server? ... is the the application server safe from attacks that may affect it as the ... technology powered by the award-winning FoundScan engine. ...
      (Pen-Test)
    • RE: *** GMX Spamverdacht *** Remotely starting the "server" process on win XP
      ... you can do the first option from computer management, but it does not work if the server service is not running on the remote machine. ... limited by the amount of fun I can have because the Server process is ... technology powered by the award-winning FoundScan engine. ...
      (Pen-Test)
    • Re: F5 and similar
      ... Seeing that we are on the BigIP topic. ... >> does it just simply redirect to the server? ... > of the server, however the L3-7 attacks will then pass, unless suitable ... > contain network/application security features found in other products, ...
      (Pen-Test)
    • Re: F5 and similar
      ... If they are using the SSL-Accelerator (which is a seperate box than ... > BigIP for load balancing and ssl acceleration. ... > does it just simply redirect to the server? ... > is the the application server safe from attacks that may affect it as the ...
      (Pen-Test)
    • RE: *** GMX Spamverdacht *** Remotely starting the "server" process on win XP
      ... This will only work as long as the server service is started... ... Give it the IP address of the remote machine, ... limited by the amount of fun I can have because the Server process is ... technology powered by the award-winning FoundScan engine. ...
      (Pen-Test)