RE: NT/2000 vs Unix based Web Servers

From: Steve Bremer (steveb@nebcoinc.com)
Date: 07/12/02


From: "Steve Bremer" <steveb@nebcoinc.com>
To: "Trevor Cushen" <Trevor.Cushen@sysnet.ie>
Date: Fri, 12 Jul 2002 12:59:53 -0500


> Because if you are allowing port 80 through on your firewall and the
> web server is badly or insecurely configured then exploits like
> MSADC.pl can be used with ease against your web server.

This is a very important point here that Trevor has made. Your
"standard" packet filtering firewall can only protect those services
which you don't wish to expose to the Internet.

I say "standard" because you can use something like hogwash to
scrub out any malicious packets at your firewall. At this point
though, it may not be considered a packet filtering firewall anymore.

Steve



Relevant Pages

  • Re: disconnect a hacker
    ... My Web server station is right next ... my attention divided by security concerns... ... see an IP connected to port 80, ... I've been forwarding my firewall logs to my ISP, ...
    (alt.computer.security)
  • Re: Firewall on server itself
    ... Perhaps the iptables could defend against an intruder who is already ... Firewall vender specific vulnerabilities ... >> be configured to protect the web server as well other computers on ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • Re: [fw-wiz] Using SSL accelerators in firewalls
    ... It also depends on what you're using your SSL for, and how tightly you can couple ... your firewall with your web application. ... web server don't have to be very aware of each other. ... >> lost in the process and the security of transactions eroded. ...
    (Firewall-Wizards)
  • Re: security advice (possible hacker activity?)
    ... > trojan or worm is installed onto the web server. ... > itself through the firewall to an email user on a PC, ... > the IIS web server. ... IWAM runs any site with Access or SQL. ...
    (microsoft.public.inetserver.iis.security)
  • Re: security advice (possible hacker activity?)
    ... > trojan or worm is installed onto the web server. ... > itself through the firewall to an email user on a PC, ... > the IIS web server. ... IWAM runs any site with Access or SQL. ...
    (microsoft.public.win2000.security)

Loading