Re: Link from corperate site to internal corp. network

From: dwarkeeper (dwarkeeper@hotmail.com)
Date: 08/04/02


From: "dwarkeeper" <dwarkeeper@hotmail.com>
To: "Leonard Leblanc" <lleblanc@emergeknowledge.com>, <security-basics@securityfocus.com>, <brahma@mendolink.com>
Date: Sun, 4 Aug 2002 04:26:26 -0400

When you say u are going to provide a link to the intranet machine /server,
either u have to NAT or some how point to the machine so external access
(internet access) is allowed directly to the "internal server". Thus in all
essence you are giving direct internet connection to a machine on your
"internal server". Thus if potentially some exploit exists on ur internal
server a malicious user can gain access not only to that "internal server",
but potentially install sniffers and other software to get direct access to
your entire internal network. Thus the concept of DMZ's and thus the concept
of segmentation of networks and switches etc.

DK
----- Original Message -----
From: "Leonard Leblanc" <lleblanc@emergeknowledge.com>
To: <security-basics@securityfocus.com>
Sent: Friday, August 02, 2002 1:00 PM
Subject: Re: Link from corperate site to internal corp. network

> I'm actually battling this same issue myself right now. The only problem I
> could see this causing is simply making fingerprinting easier for the
> hackers. Other than that, I don't see any problems, but I would definately
> be interested in hearing others comments.
>
> Leonard Leblanc
>
> ----- Original Message -----
> From: "Chris" <brahma@mendolink.com>
> To: <security-basics@securityfocus.com>
> Sent: Thursday, August 01, 2002 1:33 PM
> Subject: Link from corperate site to internal corp. network
>
>
> > I am just curious what other professionals out their think of this. I
> have
> > been forced into letting our web dev dept. put a link on a company web
> site
> > to the internal network which is on private IP's. What security
problems
> > can this cause. I don't really see an obvious issue but I just don't
like
> > the idea myself.
> >
> > Thank You,
> >
> > Chris D.
> > Network Security
> > Mendo Link, LLC
> >
> > "An Ounce Of Prevention Is Worth A Pound Of Cure."
> > Om Namo Narayanaya
> >
> >
>
>



Relevant Pages

  • drone armies C&C report - July/2005
    ... 3356 LEVEL3 Level 3 Communications ... 3491 BTN-ASN - Beyond The Network A ... 3801 MISNET - Mikrotec Internet Ser ... 15857 DIALOG-AS DIALOG-NET Autonomuo ...
    (Bugtraq)
  • Masquerading problem... can you help?
    ... server to masquerade a simple network and allow access to ... My server uses a modem to dial the internet. ... `SuSE-FW-DROP-DEFAULT' ...
    (comp.os.linux.security)
  • Re: U.S. as Traffic Cop in Web Fight
    ... Internet providers to treat all Web traffic equally, ... Digits: What Is Net Neutrality? ... AT&T cited network congestion concerns. ... Phone companies including AT&T have argued that they can live with the FCC's ...
    (talk.politics.guns)
  • U.S. as Traffic Cop in Web Fight
    ... Internet providers to treat all Web traffic equally, ... Digits: What Is Net Neutrality? ... AT&T cited network congestion concerns. ... Phone companies including AT&T have argued that they can live with the FCC's ...
    (talk.politics.guns)
  • Re: Verizon rules the World? Or just the U.S.?
    ... Internet these days? ... network can now branch anywhere, and network data transfer is a piece ... Nearly all computer science departments and many private computer ... all these networks have gateways to the NSF backbone.) ...
    (rec.arts.mystery)

Loading